Getting Data In

messy code from inputted .xlsx files

lllidan
New Member

when i try to input some excel files named xx.xlsx , and then i got some messy codes from search result like: "Pk\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00......." . that's unreadable !
how i can correctly input the kind of .xlsx files ? which source / sourcetype / index should i select ? or maybe i should use some plugins ?

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion

hello there,

Excel files are binary files, not text files
convert to csv format (save as csv), index and enjoy the data
see detailed answers here:
https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html
https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html

hope it helps

View solution in original post

0 Karma

inventsekar
Ultra Champion

Excel files are microsoft window's proprietary product and we can not load excel files directly to splunk.

so, first you have to "export / save as" the excel files to a CSV file. then the csv file can be loaded to splunk.

more on this topic...
https://www.splunk.com/blog/2015/01/30/working-with-spreadsheets-in-splunk-excel-csv-files.html

0 Karma

niketn
Legend

@lllidan , you can upload CSV format data not Excel format to Splunk.

However, you can try out Protocol Data Input created by @Damien Dallimore (BaboonBones Ltd.) for binary format data and code your own Event Handler to process and transform data as per your need. http://www.baboonbones.com/blog/get-binary-data-splunk/

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

adonio
Ultra Champion

hello there,

Excel files are binary files, not text files
convert to csv format (save as csv), index and enjoy the data
see detailed answers here:
https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html
https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...