Splunk Search

Extract field names from CSV header

JIthesh_Kumar
Explorer

Hi Team,
my CSV file contains a field like bellow (1st line in CSV) How can i create transformation for field extraction 

"State","Location name","Primary Number"

its retrieving a field state and Location

Expected Fields:
State
Location name
Primary Number

Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

You needs are probably better served by INDEXED_EXTRACTIONS=csv (index time extraction) or KV_MODE=csv (search time) in sourcetype.  Using regex to handle structured data like CSV is very fragile.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

If your column order is known and does not change, you can define delimiter-based extractions in props.conf for your sourcetype. But then you must explicitly name the fields and their order. Otherwise the only way to handle such file is using indexed extractions (which has its own drawbacks). Remember that indexed extractions happen on the initial forwarder!

isoutamo
SplunkTrust
SplunkTrust

If you can define which line contains headers and which values, then you can do this with any countable columns. It’s enough to known how many columns you could maximum have.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this is doable, but probably it needs some way to recognize which line is header line. And position in file is not that. But as @yuanliu said it's much better to use INDEXED_EXTRACTIONS=csv and then define HEADER_FIELD_LINE_NUMBER if it didn't recognize automatically that header line.

You should put props.conf also on your UF to get this work.

Structured Data Header Extraction and configuration

r. Ismo

yuanliu
SplunkTrust
SplunkTrust

You needs are probably better served by INDEXED_EXTRACTIONS=csv (index time extraction) or KV_MODE=csv (search time) in sourcetype.  Using regex to handle structured data like CSV is very fragile.

Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...