my problem is, that splunk dont regognise / use the header infomations and dont split per line.
i tried with probs.conf CSV option, header check, filds delmiter, header delimter, quotes option, field names, etc etc...
All options displays the same result... the header as event and one of the lines (randomly) as event...
you can use Settings -> Add Data wizard to get the parsing right. Here are the settings that I got using wizard:
[ yourcsvsourcetype ]
you have to put this configuration on universal forwarder or where splunk reads the file, not on indexer or on search head. As mentioned in props.conf:
This setting applies at input time, when data is first read by Splunk software, such as on a forwarder that has configured inputs acquiring the data.
Additionally you have to set KVMODE=none on SH. Which time field should be used as time source is up to you, use TIMESTAMPFIELDS for it.