Splunk Enterprise

Splunk Add-on for AWS - Ingesting csv files and he fields are not getting extracted at all

izzie123
Path Finder

Hello,

We are ingesting csv files from a S3 bucket using the Custom SQS based S3 input.

Although, the data is pulled rightly, the fields are not getting extracted properly. The header line has been ingested as a different event and the header fields are not getting extracted.

I have defined the Indexed_Extractions=csv in the props.conf

Is there any other way to extract a csv file from the S3 bucket? Any work around?

 

Labels (3)
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...