Splunk Enterprise

Lookup editor upload showing merged column fields

Bujji2023
Observer

Need help sorting out the issue that I'm having with the lookup editor.

I have successfully uploaded the csv into Splunk via the lookup editor. It shows up correctly when I run 
| inputlookup sample.csv. But when I check in the lookup editor, all the column fields are merged into one. It's showing incorrectly. I have to edit the lookup and need this to be fixed. Has anyone experienced this issue before?

Thanks

Labels (1)
Tags (1)
0 Karma

KendallW
Contributor

Hi @Bujji2023 , I had experienced similar issues when saving the lookup csv file in MS Excel before uploading. This can be fixed by saving the csv file from a text editor instead, making sure to remove any superfluous characters (e.g. quotation marks) 

0 Karma
Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...