Splunk Search

What does SearchResults "Corrupt csv header" mean?

Lowell
Super Champion

Does anyone know what this message means?

06-14-2010 15:45:14.859 WARN SearchResults - Corrupt csv header, 2 columns with the same name 'ipstr' (col #6 and #2, #6 will be ignored)

0 Karma
1 Solution

Lowell
Super Champion

Think I found the problem. A had a saved search with the following fields search command:

... | fields + user,flags,ipstr,pid,logontime,ipstr,rip,dur_mins,eventcount

Looks like I accidentally listed the "ipstr" field twice. Whoops.

View solution in original post

Lowell
Super Champion

Think I found the problem. A had a saved search with the following fields search command:

... | fields + user,flags,ipstr,pid,logontime,ipstr,rip,dur_mins,eventcount

Looks like I accidentally listed the "ipstr" field twice. Whoops.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...