Splunk Search

How to configure Splunk to index PSV files and extract field names from the header/first row?

dhavamanis
Builder

We are trying to index a psv file into Splunk with sourcetype as "psv", but its not extracting fields from the PSV's first row. Can you please provide the config to add fields as psv header/first row values.

0 Karma
1 Solution

dhavamanis
Builder

Thanks, configured props.conf at forwarder end and its working fine.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.