I'm using python SDK to search and retrieve results in JSON output_mode. The data I'm searching for was loaded into splunk as a CSV file with the first row as header. Currently I'm getting these keys in the output "_bkt","_cd","_indextime","_raw","_serial","_si","_sourcetype","_time",host,index,linecount,source,sourcetype,"splunk_server" _raw field has a string of comma separated values(actual data). I'm not able to get the header for these values. The rest of the fields are just metadata. How do I get the CSV header in the JSON output of the search? I even tried CSV 'output_mode'. No luck
... View more