Splunk Search

Remove the first line of CSV to index in splunk

Mayanakhan
Explorer

I have a CSV file which first row contains the hear fields and remaining rows contains values as below. 

name,application,targeturl,type
ABC,Desktop,google.com,chrome
XYZ,IOS,facebook.com,App
GHI,Andriod,twitter.com,App
KLM,Desktop,gmail.com,firefox

 I have added props.conf as below.

[pp_appeaser]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
HEADER_FIELD_ACCEPTABLE_SPECIAL_CHARACTERS=_
KV_MODE=none
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true

 

In search the header fields are getting as fields and as well as values as below.  also i have tried CHECK_FOR_HEADER" and "HEADER_FIELD_LINE_NUMBER=1" stanzas but i have same results.  

Mayanakhan_0-1603900804912.png

 

Can you please suggest how can i resolve this issue, so the name of headers should not index as values. 

 

0 Karma

Azeemering
Builder

HEADER_FIELD_LINE_NUMBER=2 ?

0 Karma
Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...