Splunk Enterprise

Why is my CSV index renaming the first field to some random field name?

Path Finder

Couple of my CSV indexes in Splunk (UF to Indexers) have been creating/renaming the first field in CSV with special prefixes for example Id is becoming xE2_x81, and ReportID becoming  xE2_x81ReportID or  xE2_x90ReportID, and it is changing to new name automatically after few days. Any help in fixing is appreciated. Thanks in advance. 

Labels (2)
Tags (2)
0 Karma


It seems that you might have some hidden characters in your original data. Open the file with e.g. VS Code and enable the the render control characters in the settings to check if there are hidden characters there.

Hope I was able to help you. If so, some karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...