I have a fairly complicated set of searches to create reports for Nessus vulnerability data. One thing I notice is that when I output the results to csv using outputcsv, not all of the columns are ending up in quotes. This is what the header row looks like:
All of the quoted fields have underscores, which are often created by splunk because it converts spaces to underscores. If you change your output to AS something without a space or underscore the quotes might go away.
Excel will import the example given as csv, but some fields will have quotes.
Craig, did you ever got a resolution to your issue? My issue is similar but it is the opposite; I would like to know if Splunk can strip off the quotes thru some command or some parameters of outputcsv because the system the i am sending the output csv file does not like qoutes