Splunk Search

Event breaking to middle text at index time

Dov1
Observer

Hello,

I have some text I indexing, In the middle I have csv table, and some information at end, look like this

Text text text text.

#begining of csv#

Aa,BBC,cc,dd

22,1,444,2

44,22,11,3

#end of csv#

Text text text

How to index only the lines in the csv as events

Thank you

Dov

Labels (1)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Unless the csv data is in some distinct easy distinguishable format, there's no way to filter out events based on other events. Events go through ingestion pipeline one at a time and there is no global state you can rely on (to remember whether you already met the header or footer of the data part). With small chunks of this csv data you could try to do some magic involving event breaking so that input is broken on the csv header but it'd be highly ineffective and prone to errors. And you'd get a single event consisting of whole csv content, not separate csv lines and that's probably not what you want.

I'd go for scripted/modular input but that requires some development.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...