Hello,
I wrote a PROPS Configuration file for following csv file but getting error message. Any help will be highly appreciated. Thank you so much.
[ csv ]
SHOULD_LINEMERGE=false
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
TIME_FORMAT=%Y%m%d %H:%M:%S:%Q
HEADER_FIELD)LINE_NUMBER=1
TIMESTAMP_FIELDS=TIMESTAMP
category=Structured
@SplunkDash try below you have to deploy them to UF.
[ csv ]
SHOULD_LINEMERGE=false
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
TIME_FORMAT=%Y%m%d %H:%M:%S:%3Q
HEADER_FIELD_LINE_NUMBER=1
TIMESTAMP_FIELDS=TIMESTAMP
category=Structured
@SplunkDash try below you have to deploy them to UF.
[ csv ]
SHOULD_LINEMERGE=false
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
TIME_FORMAT=%Y%m%d %H:%M:%S:%3Q
HEADER_FIELD_LINE_NUMBER=1
TIMESTAMP_FIELDS=TIMESTAMP
category=Structured
Thank you so much. But, still getting error message...Failed to parse timestamp!!!
@SplunkDash Your field name in CSV seems TimeStamp (camel case), what you have set TIMESTAMP_FIELDs = TIMESTAMP (caps) can you correct it to match with CSV header names.
oops ...😀 cool working as expected, thank you so much, appreciated!!!