Splunk Enterprise Security

Importation and visualisation of CSV issue

nathanboon
Engager

Hello, 

I have a CSV dataset with 2 colomns (_time , temperature) but when i import the dataset in Splunk to do a visualization of the dataset, Splunk plot the dataset with the temperature as the X value and the time as a Y value. How can I change the two columns? 

I tried to modify directly the CSV file but doesn't change anything.

nathanboon_0-1616508843910.png

nathanboon_1-1616508904826.png

Thanks 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Just select time range as All time on top right. It is now showing last 24 hour. That is why you don't see events.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Please try with "All time". Because your dataset has timestamps with year 2010. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

nathanboon
Engager

Sorry i'm new with Splunk and i don't where i have to type "all time"

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @nathanboon,

I see a warning on your screenshot top-left stating that _time should be UNIX time. I think your CSV timestamps are not epoc. Can you please change the search like below;

| inputcsv dataset.csv 
| eval _time=strptime(_time,"%Y-%m-%d %H:%M")
| table _time temperature

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

nathanboon
Engager

I change the command but now Splunk doesn't recognize the dataset anymore

nathanboon_0-1616597427780.png

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried using the table command to specify the field order?

| inputcsv dataset.csv | table _time temperature
---
If this reply helps you, Karma would be appreciated.

nathanboon
Engager

Yes i tried this and it's works , the visualization is good however when i'm trying to apply a filter kalman, it doesn't show anything:

nathanboon_0-1616513575290.pngnathanboon_1-1616513595105.png

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The instructions at https://docs.splunk.com/Documentation/MLApp/5.2.1/User/FTSExperiment#Assistant_workflow say to specify a Period.  Have you tried that?

---
If this reply helps you, Karma would be appreciated.
0 Karma

nathanboon
Engager

I specify the period of 1 year (365) but the result is the same.

I tried many different configuration but Splunk doesn't plot anything.

nathanboon_1-1616595411311.png

 

nathanboon_0-1616595385377.png

 

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...