Hi @gcusello I can delete the top line out before I send it to Splunk, as the Search is easier to understand and looks nicer. So in the Field Data I only have the Values without the Header. My Question is, this | rex field=Data "\"(?<Name>[^\"]*)\",\"(?<Website>[^\"]*)\",\"(?<Country>[^\"]*)\"" Only reads out the first line. The thing is, that when I write the values from the csv-File into a Log-File, it adds all rows together so if it was: Line 1 Line 2 Line 3 In the Log it will be: Line 1 Line 2 Line 3 So if I have this in the CSV "Thomas","thomas.com","England" "Luca","luca.com","USA" In the Log-File and therefore also in the Field of the event it looks like this: "Thomas","thomas.com","England" "Luca","luca.com","USA" Now my Question was, if it is possible to make a table with only one Event, which has all Lines in it and if yes, how do the Lines have to be Formatted in the Log and how does the rex look like to show it like this: (Here I made 2 Events, for every line a sepearate Event)
... View more