Splunk Search

How can I change delimiter on outputcsv ?

macewindum
Engager

I want to know how can I change the delimiter on a result file generate by outputcsv commands ?
I want to use ";" as delimiter instead of ",".

Tags (1)

grijhwani
Motivator

You do not have that option on export. You will have to post-process it somehow.

If you work on Linux there are a number of command line options which could help. Depending on whether you have any embedded commas a simple edit with global replace, or sed or awk script would suffice. Or load into a spreadsheet tool (be that Libreoffice or MS Excel, etc) and re-export.

After cursory investigation, it appears that the python CSV module has parameters for delimiters, etc. but the export dialogue makes no allowance for using them.

0 Karma

jmorais
Explorer
0 Karma

Anam
Community Manager
Community Manager

Hi jmorias

Downvoting users should be reserved for suggestions that could be potentially harmful to someone's Splunk environment. Also, giving a reason as "we have other options" is inappropriate and unnecessary, and this is not how Splunk community etiquette works in this forum. The downvote form is supposed to be used to help educate the community to learn and improve based on the context provided. Simply commenting with your suggestion without downvoting would have been helpful and constructive.

Some of the most active members in Answers have helped set the standard of how voting etiquette should work in the Splunk community which distinguishes our culture apart from other Q&A forums. Upvote early and often to give credit where it’s due for high-quality posts, comment where you think feedback needs to be given, and only downvote if something potentially dangerous is suggested. If you’re interested in seeing how this voting etiquette was developed, check out this Splunk Answers post: https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

0 Karma

jmorais
Explorer

ok, sorry ... I will follow the sugestion for the next votes.

0 Karma

Anam
Community Manager
Community Manager

Hi @jmorais

Thanks for understanding and being receptive to the Splunk community forum and culture. We hear from users in the community very often that they appreciate feeling like they can contribute here without the fear of being shunned so quickly by others like they experience in other forums. So, we just want to maintain that positive and constructive environment.

Thanks for contributing your knowledge here with the Splunk Community!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...