paddy, The scenario you described works for me. I was able to read in and display all fields from a csv file that looks like
EventValueFilter,Duration,Earliest,Limit
"EVENTA","1000"," ","| head 5 "
"EVENTB","2000"," ","| head 5 "
"EVENTC","3000"," ","| head 5 "
I've only tested on a Mac, but it should work for splunk running on unix and windows. What OS are you running on? What version of splunk? Can you send a screen shot of the output you are seeing?
Regarding the map issue. I'm not sure I understand the question. Can you explain in more detail.
... View more