Splunk Enterprise

Removing header from CSV file

krish5vuda
Engager
  • I have a CSV file placed in a UF and the CSV data is as follows

'"Name" "userid" "use location" "userdesignation"'

Raj raj-123 Argentina Consultant 

Now  I have written props and transforms as below but still the header is being ingested 

 

Props:

[Sourcetype]

Should_linemerge=false 

Line_Breaker=([\r\n]+)

NO_BINARY_CHECK=true 

CHARSET= UTF-8 

INDEXED_EXTRACTIONS=CSV 

category=structured 

description=Comma-separated value format. Set header and other settings in "Delimited Settings"

disabled=false

TRUNCATE=99999

DATETIME_CONFIG=CURRENT

KV_MODE=none 

HEADER_FIELD_LINE_NUMBER=1 

TRANSFORMS-set=setnull 

 

 

Transforms.conf 

[setnull]

REGEX=(^"NAME".*$) |(^\'\"NAME\".$)

DEST_KEY=queue 

FORMAT=nullQueue 

Please let me know what changes has to be made so that header is not being ingested 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you try this on UF? In UF you cannot use transforms.con and actually you shouldn’t need it as you told that headers are in first row in file. And remember to restart UF after put props.conf there. 

0 Karma

krish5vuda
Engager

This conf are  in indexer and not in UF

0 Karma

isoutamo
SplunkTrust
SplunkTrust

He is instructions where those files should be in different cases https://wiki.splunk.com/Community:HowIndexingWorks and https://www.aplura.com/assets/pdf/where_to_put_props.pdf. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...