Splunk Search

Remove the first line of CSV to index in splunk

Mayanakhan
Explorer

I have a CSV file which first row contains the hear fields and remaining rows contains values as below. 

name,application,targeturl,type
ABC,Desktop,google.com,chrome
XYZ,IOS,facebook.com,App
GHI,Andriod,twitter.com,App
KLM,Desktop,gmail.com,firefox

 I have added props.conf as below.

[pp_appeaser]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
HEADER_FIELD_ACCEPTABLE_SPECIAL_CHARACTERS=_
KV_MODE=none
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true

 

In search the header fields are getting as fields and as well as values as below.  also i have tried CHECK_FOR_HEADER" and "HEADER_FIELD_LINE_NUMBER=1" stanzas but i have same results.  

Mayanakhan_0-1603900804912.png

 

Can you please suggest how can i resolve this issue, so the name of headers should not index as values. 

 

0 Karma

Azeemering
Builder

HEADER_FIELD_LINE_NUMBER=2 ?

0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...