Hi,
I have a script which output a csv file :
id,name,env,start,end
1234,test,[env]:dev,2020-12-31 18:07,2020-12-31 19:07
The first line is the header and ALL lines in file must be reindexed each time there is a modification (adding or a suppression).
I have an inputs.conf like this :
[monitor:///opt/splunk/etc/apps/my_app/bin/my_csv.csv]
index = test
sourcetype = st
disabled = 0
initCrcLength = 3000
I have a props.conf like :
[st]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = csv
KV_MODE = none
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true
The indexation is really weird : it actually index only the header :
Can you help me please ?
Thank a lot.
Hi @mah,
did you fixed the problem? Im currently facing the same.