I've just created a brand new csv and indexed it with the following:
props.conf
[indexed_extractions_test]
HEADER_FIELD_LINE_NUMBER=1
FIELD_DELIMITER=,
INDEXED_EXTRACTION = csv
csv-
os,range
AIX:Version,aix
FreeBSD:Version,freebsd
HPUX:Version,hpux
Linux:Version,linux
OSX:Version,osx
Solaris:Version,solaris
Unix:Version,unix
$splunk_home/bin/splunk add oneshot -index main -sourcetype indexed_extractions_test
The results are accurate. CSV is indexed without the header, and I have KV pairs for os=*:Version and range=solaris etc.
Make sure you are deleting the old indexed data before rerunning it.
... View more