Splunk Search

Quoting values and CSV export

benton
Path Finder

If I run this search I generate two numeric fields, one called number the other called decimal

 

 

| makeresults 1
| eval number = 7
| eval decimal = 7.0

 

 


When I choose to export this data as CSV there are quotes around decimal but not around number.  Is it possible to ensure that neither field has quotes when the CSV is downloaded?

benton_0-1626377103705.png

 

Labels (1)
0 Karma

benton
Path Finder

Thank you for the reference! I hadn't seen that post yet, but it's not working as expected, or I'm misunderstanding that post, or maybe it's because my problem is with using the Splunk web UI to export the CSV to my local computer. My search doesn't involve the outputcsv command. In any case, the behavior is consistent, if the number contains a decimal then it is quoted. If it doesn't contain a decimal it is not quoted. I think this is related to the UI download behavior itself and maybe I can't overcome it via a change to the search.

| makeresults 1
| eval number = 7
| eval decimal = 7.0
| eval never_quotes = trim(decimal, "\"")


You'll notice that never_quotes still contains quotes.  

benton_0-1626378542431.png

 

0 Karma

efika
Communicator

This seems to be how CSV is working. Note that the header says that it is recognized as a decimal number.
What you are trying to do with the exported CSV ?

0 Karma

benton
Path Finder

A user clicks the export button from a dashboard and then that file is manually fed into an application that runs on the local computer. Except that application is expecting that all numbers will not be quoted.  As a work-around the users are currently exporting the file from Splunk, opening it in Excel, and then closing/saving as CSV.  Excel seems to automatically resolve the issue during the save by removing all the quotes from numeric fields.  The actual file also includes text columns with spaces that require quotes.  It seems like Excel automatically and correctly maintains the quotes when needed and removes them when not needed.

0 Karma

efika
Communicator

So it seems that the other application is pointed to the var\run\splunk\csv to read the exported files ?

One option to tackle your situation is to point the importing application to a different folder and use a cron/scheduled task to read the splunk CSV files, SED the unneeded quotes and write the files to this new folder.

0 Karma

benton
Path Finder

@efika wrote:

So it seems that the other application is pointed to the var\run\splunk\csv to read the exported files ?

One option to tackle your situation is to point the importing application to a different folder and use a cron/scheduled task to read the splunk CSV files, SED the unneeded quotes and write the files to this new folder.


The other application runs locally (as does Excel) and we do not allow these local computers to have access to the Splunk server directly. 

0 Karma

efika
Communicator

You can still run the scheduling task on the splunk server itself and let it copy to the other machines so you continue to adhere to the described design.

0 Karma

efika
Communicator
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...