Hi nagarjuna280,
at first, only with csv files, you have to deploy props.conf and transforms.conf both on indexers and forwarders.
anyway, your props.con must be something like this
[ csv ]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
KV_MODE=none
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true
if there isn't the header with fieldnames add
FIELD_NAMES=field1, field2, field3, ...
I suggest to use the Add data function of the Splunk web interface to test your field extraction.
Bye.
Giuseppe
... View more