Trying to index a CSV, but only the first two lines are indexing. I want to skip the first line and start indexing the data from the headers for the columns
Splunk Search output
TYPE Selected.Microsoft.ActiveDirectory.Management.ADAccount,,
LastLogonDate,Name,LockedOut
CSV input file
TYPE Selected.Microsoft.ActiveDirectory.Management.ADAccount,,
LastLogonDate,Name,LockedOut
25/05/2016 2:13,SPKTest3,TRUE
25/05/2016 2:13,SPKTest4,TRUE
Props.conf
[ADAcount]
HEADER_FIELD_LINE_NUMBER=2
INDEXED_EXTRACTIONS = csv
FIELD_DELIMITER=,
input file
[monitor:...//test.csv]
disabled = false
sourcetype =ADAcount
index = test
... View more