Knowledge Management

CSV Field indexing

TISKAR
Builder

Hello,

I have a CSV file that I monitor via the Universal Forwarder (UF). I’m encountering an issue where sometimes I cannot find the fields in Splunk when i run index=myindex, even though they appear on other days.

The CSV file does not contain a header, and the format of the file is the same every day (each day starts with an empty file that is populated later). Here is the props.conf configuration that I’m using:

 

 

[csv_hff]
BREAK_ONLY_BEFORE_DATE = 
DATETIME_CONFIG = 
FIELD_NAMES = heure,id,num,id2,id3
INDEXED_EXTRACTIONS = csv
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = heure
TIME_FORMAT = %d/%m/%Y %H:%M:%S
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

 

 

Has anyone else encountered the same problem?

Splunk version 9

Thank you

Labels (1)
Tags (3)
0 Karma

TISKAR
Builder

@PickleRick @ Events are indexed, but fields are not extracted for the same day. For other days, there is no problem

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check those events - my hunch is there is something wrong with formatting in those rows - some inconsistent quoting or something like that.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

But are the events indexed but the fields are not extracted or are the events not ingested at all?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...