Need help sorting out the issue that I'm having with the lookup editor.
I have successfully uploaded the csv into Splunk via the lookup editor. It shows up correctly when I run
| inputlookup sample.csv. But when I check in the lookup editor, all the column fields are merged into one. It's showing incorrectly. I have to edit the lookup and need this to be fixed. Has anyone experienced this issue before?
Thanks
Hi @Bujji2023 , I had experienced similar issues when saving the lookup csv file in MS Excel before uploading. This can be fixed by saving the csv file from a text editor instead, making sure to remove any superfluous characters (e.g. quotation marks)