Splunk Enterprise

Lookup editor upload showing merged column fields

Bujji2023
Observer

Need help sorting out the issue that I'm having with the lookup editor.

I have successfully uploaded the csv into Splunk via the lookup editor. It shows up correctly when I run 
| inputlookup sample.csv. But when I check in the lookup editor, all the column fields are merged into one. It's showing incorrectly. I have to edit the lookup and need this to be fixed. Has anyone experienced this issue before?

Thanks

Labels (1)
Tags (1)
0 Karma

KendallW
Contributor

Hi @Bujji2023 , I had experienced similar issues when saving the lookup csv file in MS Excel before uploading. This can be fixed by saving the csv file from a text editor instead, making sure to remove any superfluous characters (e.g. quotation marks) 

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...