Getting Data In

messy code from inputted .xlsx files

lllidan
New Member

when i try to input some excel files named xx.xlsx , and then i got some messy codes from search result like: "Pk\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00......." . that's unreadable !
how i can correctly input the kind of .xlsx files ? which source / sourcetype / index should i select ? or maybe i should use some plugins ?

Tags (2)
0 Karma
1 Solution

adonio
Ultra Champion

hello there,

Excel files are binary files, not text files
convert to csv format (save as csv), index and enjoy the data
see detailed answers here:
https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html
https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html

hope it helps

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Excel files are microsoft window's proprietary product and we can not load excel files directly to splunk.

so, first you have to "export / save as" the excel files to a CSV file. then the csv file can be loaded to splunk.

more on this topic...
https://www.splunk.com/blog/2015/01/30/working-with-spreadsheets-in-splunk-excel-csv-files.html

0 Karma

niketn
Legend

@lllidan , you can upload CSV format data not Excel format to Splunk.

However, you can try out Protocol Data Input created by @Damien Dallimore (BaboonBones Ltd.) for binary format data and code your own Event Handler to process and transform data as per your need. http://www.baboonbones.com/blog/get-binary-data-splunk/

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

adonio
Ultra Champion

hello there,

Excel files are binary files, not text files
convert to csv format (save as csv), index and enjoy the data
see detailed answers here:
https://answers.splunk.com/answers/568971/what-is-the-best-way-to-index-excel-sheet-to-splun-1.html
https://answers.splunk.com/answers/327256/when-indexing-an-excel-file-with-the-xlsx-file-ext.html

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...