Found a way to spot the troublesome csv. (worked for me, anyway) requires CLI. The grep looks for special characters in the file. find $SPLUNK_HOME/etc -name "transforms.conf" | xargs grep -l -P -n "[\x80-\xFF]"
find $SPLUNK_HOME/etc -name "*.csv" | xargs grep -l -P -n "[\x80-\xFF]" Another thing that helped track down the issue was run the rest call as a Splunk search, then look at the search.log | rest /services/data/transforms/lookups
... View more