Other Usage

csv report has some lines split in multiple cells

nicofantinato
Path Finder

Hi all,

tabled results from a scheduled search are sent via email as a csv attached. Some rows could be very long so in some cases, when I open that csv file with Excel, I find some "split rows", I would expect one unique line per row but instead sometimes I have half line positioned in the second column (as in the screenshot below).

nicofantinato_0-1634128333143.png

I'd like to obtain only one entire line per row,  so every event only in the first column of the Excel.

The source search finds some events and tables some fields as result.

Thanks in advance for any hint.

Labels (1)
0 Karma

nicofantinato
Path Finder

I found out that Excel rows are splitted in multiple columns when semicolon character is used. I want to highlight that I have this problem both when I use export button on a search results and when reports send emails with csv attached.
For example, this is a screenshot of the search result:

nicofantinato_0-1635165956313.png

and this is how I find events for "Result" field once I export them and I open them in Excel:

nicofantinato_1-1635166171314.png

with the line splitted when it encounters a semicolon.

Is there a way to change CSV delimiter for export action or other options? Do I have to set a custom sendmail.py for my app?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...