Getting Data In

Fields are missing from some of my records after importing a CSV file

ianthebrave
New Member

Hi!

I imported a CSV file with 97 fields and after doing some searches, some fields are missing for some records. I have this so-called 'close_notes' field and it's present to some of the records while there are a few records where it does not exist.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ianthebrave, if cusello answered your question please remember to accept the answer to both close this question and to award karma points. Happy splunking! 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

Sukisen1981
Champion

I second Giuseppe, look closely at your CSV and splunk events, your events will be separated by a , in the splunk events, it is possible that the data input field from your CSV is having some issues. There is no way that once uploaded, the splunk index misses some while accepting some close_notes field values. Have you checked if the fields in CSV BEFORE this field in your CSV is not blank / empty for some rows in the CSV?

0 Karma

gcusello
SplunkTrust
SplunkTrust

If this answer satisfies your question, please accept or upvote it.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...