I am indexing a CSV file into Splunk and wish to display the row number in a seperate column called 'row count'.
Field 1 Field 2 Row Count Field 3
blah blah 1 blah
blah blah 2 blah
blah blah 3 blah
What is the best method to achieve this?
Add ... | streamstats count as "Row Count" to your search
... | streamstats count as "Row Count"
Would displayRowNumbers work here? If so, how would it be configured in my search query?
you can set this in viewstates.conf or in your XML with this option:
This will work in the recent Splunk releases.
Adding to /opt/splunk/etc/apps/search/local/viewstates.conf does not seem to do anything in the search app.