Getting Data In

csv headers are not getting listed

Gowthamdevaraj
New Member

Hello,

I have clonned the CSV source type in Splunk and created a new CSV sourcetype as Alpha_csv and configured to monitor the csv files.

I have created a deployment apps and configured inputs.conf in deployment app.

All my csv files are not getting monitored but no as per header values. (no csv headers are getting listed)

csv sourcetype is set to auto, comma separated csv.

Can anyone help on this?

Thanks

Tags (2)
0 Karma
1 Solution

manjunathmeti
Champion

Along with inputs.conf you also need to copy settings for Alpha_csv in props.conf in deployment app and deploy it to forwarder server.

View solution in original post

0 Karma

manjunathmeti
Champion

Along with inputs.conf you also need to copy settings for Alpha_csv in props.conf in deployment app and deploy it to forwarder server.

0 Karma

PavelP
Motivator

Hello @Gowthamdevaraj ,
if I understand you correctly the file get monitored correctly, but you cannot see the first line of the logs with header names? This is how indexed_extraction for CSV works - your fields are get parsed and mapped to the right field taken from the header line and the header line get removed. You can access any parsed field by using the field name.

Here is more info about indexed extraction: https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/Extractfieldsfromfileswithstructureddata

Have it worked before you cloned the source type?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...