All Apps and Add-ons

Feature Request - allow 1 to represent true and 0 to represent false when importing a CSV into a KVstore with a Boolean field

chris_barrett
SplunkTrust
SplunkTrust

Background: I attempted to import a CSV file into a KV Store using v3.3.3 of the Lookup Editor app. One of the fields in the CSV uses 0 to represent false and 1 to represent true. I set the corresponding field as Boolean when I created the KV Store but when I tried to import the data the Boolean field showed "#bad-value". I found that in order to get the CSV to be successfully imported into the KV Store, I had to pre-process the script (using sed) to replace the 1's with "true" (sans quotes) and the 0's with false (again, sans quotes).

Various settings within the Splunk config files use 0 to represent false and 1 to represent true. Would it be possible to have Lookup Editor do the same when importing in to a field that has been typed as "Boolean"?

0 Karma
1 Solution

LukeMurphey
Champion

I opened a feature request to implement this: https://lukemurphey.net/issues/2606

I'm currently planning to implement this in the next feature release (3.4).

View solution in original post

0 Karma

LukeMurphey
Champion

I opened a feature request to implement this: https://lukemurphey.net/issues/2606

I'm currently planning to implement this in the next feature release (3.4).

0 Karma

woodcock
Esteemed Legend

Https://ideas.spunk.com and then post link here so we can UpVote.

0 Karma

chris_barrett
SplunkTrust
SplunkTrust

Hi @woodcock,
Lookup Editor is developed by a third-party (@LukeMurphey) and I'm of the belief that https://ideas.splunk.com is only for software developed by Splunk.

0 Karma

woodcock
Esteemed Legend

Good point. I missed the Lookup Editor part.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...