I have configured field extractions in props.conf and transforms.conf. But despite of that some values from CSV file are extracted in "_serial" field. What should I do to have proper extractions of fields.
_serial is a hidden field that Splunk puts on every event when it gives back search results. However the number is just indicating the position of each event in the result set.
So the first event in every search result will have _serial=0, the second will have _serial=1, and so on and so forth.