Splunk Search

When does splunk add double quotation in outputcsv?

yuwtennis
Communicator

Hi!

I found that when you execute outputcsv in splunk (ver 5.0.3), some fields has double quotation but some does not.
My question is ,

  1. When does splunk add the double quotation?
  2. Can you control the appearance ?

Any help is appreciated!

Thanks,
Yu

Tags (2)
0 Karma

MuS
Legend

Hi yuwtennis and sajbutler,

did some tests and here are the results: You will get double quotes when there is any special character (like . or - or a space) in the values.
Here are some simple test you can run and verify the results.

All numeric value:

index=_internal | head 1 | eval foo="19873297326501876528731" | table foo | outputcsv foo.csv

foo.csv looks like this:

cat var/run/splunk/foo.csv
foo
19873297326501876528731

All word characters value:

index=_internal | head 1 | eval foo="noQuotes" | table foo | outputcsv foo.csv

foo.csv looks like this:

cat var/run/splunk/foo.csv
foo
noQuotes

All alphanumeric with special character value:

index=_internal | head 1 | eval foo="Quotes.because.of.the.dot" | table foo | outputcsv foo.csv

foo.csv looks like this:

cat var/run/splunk/foo.csv
foo
"Quotes.because.of.the.dot"

All alphanumeric with special character value:

index=_internal | head 1 | eval foo="Quotes-because-of-the-dash" | table foo | outputcsv foo.csv

foo.csv looks like this:

cat var/run/splunk/foo.csv
foo
"Quotes-because-of-the-dash"

hope this helps ...

cheers, MuS

mvaradarajam
Path Finder

Hi MuS,

How to remove double quotes from alphanumeric?

MuS
Legend

use a trim after the lookup

... | head 1 | eval foo="\"quotes\"" | eval boo=trim(foo, "\"") | table foo boo
0 Karma

sajbutler
Path Finder

@yuwtennis Did you end up getting an answer for this?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...