Reporting

OUTPUTCSV -- No Quotes Please

vragosta
Path Finder

OUTPUTCSV is currently appending search results surrounded in quotes, like "1.1.1.1."

Is it possible for OUTPUTCSV to NOT surround the output in quotes?

Thanks!

Tags (1)

MuS
Legend

Hi vragosta,

no, this is probably done to handle any non-alphanumeric character correct. See this answer http://answers.splunk.com/answers/114632/when-does-splunk-add-double-quotation-in-outputcsv.html for more details.

cheers, Mus

0 Karma

MuS
Legend

or use a simple trim after the lookup?

... | head 1 | eval foo="\"quotes\"" | eval boo=trim(foo, "\"") | table foo boo
0 Karma

jeffreygaraygay
Explorer

Hello, were you able to get your issue with outputcsv having csv output in quotes resolved?

Thanks,
Jeff

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...