Getting Data In

csv file could not be read.

Explorer

I created a csv file and placed in splunk/var/run/splunk/csv/ folder and using the command |inputcsv filename.csv

I am unable to get the results. It says file could not be read. I have not applied any restrictions to the file. Please provide me with detailed steps on what to check .
I guess I am missing something here.

Regards,
Pallavi

0 Karma
1 Solution

Explorer

This issue is solved. I changed the permissions of the folder in which the file resides. Now i can read and write to the file.

Thanks for all responses.

View solution in original post

0 Karma

Explorer

This issue is solved. I changed the permissions of the folder in which the file resides. Now i can read and write to the file.

Thanks for all responses.

View solution in original post

0 Karma

Motivator

Place it in $splunk_home/etc/apps/search/lookup/

Run csv folder is for outputcsv

web ui to import and check where the files are imported. Why do you want to place the field in run - csv??

For further details check the below URL,
http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/ConfigureCSVlookups

0 Karma

SplunkTrust
SplunkTrust

Check the permission of the file. Make sure that the file exists and is readable by the splunk user

0 Karma

Explorer

In this you have to map the field name in the csv file with the field name you want to .
For ex. use
sourcetype=abc|lookup filename.csv field1=FIELD1 field2=FIELD2....

It is created before using lookups command.

0 Karma