I just want to index a file which has no data in it and just the headers. so that when i search for the index on the seach head i just get the headers shown without any data and the csv generated should have just the headers with no data
like @p_gurav mentioned, i am not sure regarding this requirement
also, when indexing a csv file, splunk will avoid the header if there is no values under it.
you can try and use the lookup editor app or use a lookup for this requirement.
hope it helps
Assuming you've correct configuration to parse the file data as CSV, and empty-file/just-headers, will not get indexed. Splunk stores raw data with metadata information not just the metadata. Since no results will be shown at search, you won't be able to export or outputfile or outputcsv.