Splunk Search

lookup help

changwoo
Communicator

i am trying to import a .csv but it is in txt format

and it is seperated with :: not ,

do i have to change :: to , ???

does only .csv file reads with , ?

Tags (1)
0 Karma
1 Solution

lukejadamec
Super Champion

A lookup can be either space or comma delimited. It cannot be :: delimited. You could open the file in wordpad or word and use find-replace :: with ,.

After you make the changes, save the file as a .csv.

View solution in original post

lukejadamec
Super Champion

A lookup can be either space or comma delimited. It cannot be :: delimited. You could open the file in wordpad or word and use find-replace :: with ,.

After you make the changes, save the file as a .csv.

changwoo
Communicator

Thanks for your help~!!!!! it works great

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...