Splunk Search

When launching our app, why are we getting "SearchOperator: inputcsv - Encountered 'Inconsistent number of column' errors while reading input"?

Communicator

Hello,

When I launch an App that was written and that we have here on site, I receive the following error (quite a few times)

WARN  SearchOperator:inputcsv - Encountered 11 'inconsistent number of column' errors while reading input

I have checked all of the CSV tables in this App's lookup directory and they appear to be consistent - meaning they have the same amount of columns relative to the header and the permissions are set to this App.

I also ran the searches separately from the app and there are no errors that come up in the Splunkd.log

Any ideas out there please?

Thank you

0 Karma
1 Solution

Communicator

I'll answer my own question. I had to isolate which one of the lookup csv files was complaining. After that, there were indeed 11 occurrences where there were commas in the second field thus causing this error. There were well over 1000 lines in this file, so it was a little tedious.

View solution in original post

0 Karma

Communicator

I'll answer my own question. I had to isolate which one of the lookup csv files was complaining. After that, there were indeed 11 occurrences where there were commas in the second field thus causing this error. There were well over 1000 lines in this file, so it was a little tedious.

View solution in original post

0 Karma