Splunk Enterprise

How can I configure Splunk to read a csv file from a sourcetype

leandromatperei
Path Finder

Guys

I have the following .csv file that needs to be captured by Universal Forwarder, but the data is coming in messy. Could you help me how to create a sourcetype so that they are indexed in the order of the first line?

 

"Data","Site","Tipo","Agencia","Posicao","RCAF","Nome","Status","mes_ano"
"04/03/2021","SP","Agência","1010","AS","TESTE","Claudio A.","OnHook (01:00:00)","03-2021"
"04/03/2021","","Agência","","Consultor","32323232","Claudio A.","OnHook (10:00:41)","03-2021"

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please show an example of the "messy" input.  Also, what do you mean by "in the order of the first line"?  The first line is a header that doesn't specify an order.  Besides, the forwarder always reads files from the first line to the last and there is no way to change that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...