Splunk Search

Prop Conf for CSV input data

SplunkDash
Motivator

Hello,

Please let me know how I would write Props Configuration file for this csv file. Segment of sample data for this csv file is given below. Any help will be highly appreciated, thank you!

 

malekmo_1-1626381853803.pngmalekmo_1-1626381853803.png

 

 

 

Labels (1)
Tags (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @SplunkDash 

can you try this and deploy it to UF not on HF/intermediate forwarder. Restart UF.

 

## props.conf
[your_sourcetype]
HEADER_FIELD_LINE_NUMBER = 1
INDEXED_EXTRACTIONS = CSV
DATETIME_CONFIG = CURRENT

 

--

An upvote would be appreciated and Accept the solution if this reply helps!

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @SplunkDash 

can you try this and deploy it to UF not on HF/intermediate forwarder. Restart UF.

 

## props.conf
[your_sourcetype]
HEADER_FIELD_LINE_NUMBER = 1
INDEXED_EXTRACTIONS = CSV
DATETIME_CONFIG = CURRENT

 

--

An upvote would be appreciated and Accept the solution if this reply helps!

codebuilder
Influencer

Since you have structured data with a header you can use the built-in CSV sourcetype. Just set sourcetype = csv inputs.conf on your forwarder.

Or you can create a custom one using INDEXED_EXTRACTIONS = csv
See the documentation below for details and additional settings.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Data/Extractfieldsfromfileswithstructureddata#Use...

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

SplunkDash
Motivator

Thank you. But, I used

 

DATETIME_CONFIG=current

SHOULD_LINEMERGE=false

LINE_BREAKER=([\r\n]+)

NO_BINARY_CHECK=true

CHARSET=UTF-8

EVAL-_raw=replace(_raw,"\"","")

INDEXED_EXTRACTIONS=csv

KV_MODE=none

category=Structured

but, showing no events.......when I take off "DATETIME_CONFIG=current" and leave this value blank... it's showing events with error messages ("Failed to parse timestamp"). Any help will be highly appreciated. 

 

0 Karma

codebuilder
Influencer

Where are you putting this? Also, why are you doing replacements on _raw?

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

SplunkDash
Motivator

_raw  just generated automatically from the system when I pull the source file  through SPLUNK web console to test my PROPS. It doesn't make any differences if I take off take option

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...