CSV files are output in a fixed form from other departments' systems.
I'm trying to replace the file processing Excel with Splunk.
I see, props.conf works only for indexed data..
It turns out that we need to think about different means.
Thank you for your reply many times.
(The following may be unnecessary content, sorry.
The summary of what you want to do is to load three types of standard CSV files, and output one CSV file after processing.
At that time, it is necessary to delete previous data and perform new processing.
I think this process is not suitable for Splunk, which indexes and accumulates data.
If you look only at my work on the project, it may not be worthwhile to use Splunk.
... View more