Knowledge Management

CSV Field indexing

TISKAR
Builder

Hello,

I have a CSV file that I monitor via the Universal Forwarder (UF). I’m encountering an issue where sometimes I cannot find the fields in Splunk when i run index=myindex, even though they appear on other days.

The CSV file does not contain a header, and the format of the file is the same every day (each day starts with an empty file that is populated later). Here is the props.conf configuration that I’m using:

 

 

[csv_hff]
BREAK_ONLY_BEFORE_DATE = 
DATETIME_CONFIG = 
FIELD_NAMES = heure,id,num,id2,id3
INDEXED_EXTRACTIONS = csv
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = heure
TIME_FORMAT = %d/%m/%Y %H:%M:%S
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true

 

 

Has anyone else encountered the same problem?

Splunk version 9

Thank you

Labels (1)
Tags (3)
0 Karma

TISKAR
Builder

@PickleRick @ Events are indexed, but fields are not extracted for the same day. For other days, there is no problem

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check those events - my hunch is there is something wrong with formatting in those rows - some inconsistent quoting or something like that.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

But are the events indexed but the fields are not extracted or are the events not ingested at all?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...