I have a script which output a csv file :
1234,test,[env]:dev,2020-12-31 18:07,2020-12-31 19:07
The first line is the header and ALL lines in file must be reindexed each time there is a modification (adding or a suppression).
I have an inputs.conf like this :
[monitor:///opt/splunk/etc/apps/my_app/bin/my_csv.csv]index = testsourcetype = stdisabled = 0initCrcLength = 3000
I have a props.conf like :
[st]DATETIME_CONFIG =INDEXED_EXTRACTIONS = csvKV_MODE = noneNO_BINARY_CHECK = trueSHOULD_LINEMERGE = falsecategory = Structureddescription = Comma-separated value format. Set header and other settings in "Delimited Settings"disabled = falsepulldown_type = true
The indexation is really weird : it actually index only the header :
Can you help me please ?
Thank a lot.
did you fixed the problem? Im currently facing the same.