Splunk Search

how to skip header file in csv

Gayathirikuppus
New Member

i have a csv file with header column"Name","CapacityGB","FreeSpaceGB" with the line number 1.

This header is also coming along with the next line as one single event:

I have used the below props.conf:

[xxxxx]
INDEXED_EXTRACTIONS = CSV
DATETIME_CONFIG = CURRENT
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = true
MUST_BREAK_AFTER = (\,\"\d+.\d+\"$)
FIELD_DELIMITER=,
FIELD_QUOTE="

ISSUE:

1/27/19
4:31:01.000 AM

"Name","CapacityGB","FreeSpaceGB"
"xxxxxx","1008.374375","486.1959375"

Please let me know how to exclude the header file.

Do i have to update anything on props.conf?

Tags (1)
0 Karma

lakshman239
Influencer

you may want to add the following in your props.conf your sourcetype to try and exclude the header being added to events.

HEADER_FIELD_LINE_NUMBER=1
PREAMBLE_REGEX=^\"[a-zA-Z\,\"]+

0 Karma

dkeck
Influencer

Hi,

have a look at this, and make sure you set this on your forwarder.

https://answers.splunk.com/answers/586952/how-to-skip-header-in-csv-files-before-indexing.html

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...