Splunk Enterprise

Lookup editor upload showing merged column fields

Bujji2023
Observer

Need help sorting out the issue that I'm having with the lookup editor.

I have successfully uploaded the csv into Splunk via the lookup editor. It shows up correctly when I run 
| inputlookup sample.csv. But when I check in the lookup editor, all the column fields are merged into one. It's showing incorrectly. I have to edit the lookup and need this to be fixed. Has anyone experienced this issue before?

Thanks

Labels (1)
Tags (1)
0 Karma

KendallW
Contributor

Hi @Bujji2023 , I had experienced similar issues when saving the lookup csv file in MS Excel before uploading. This can be fixed by saving the csv file from a text editor instead, making sure to remove any superfluous characters (e.g. quotation marks) 

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...