Hi all, when i do an inputcsv command, I see the data in the file I put on the splunk server. Since I want to see them as events I query the following:
| inputcsv filename.csv
(I see all the data, 7603 counted)
| inputcsv start=1 events=yes filename.csv
(I get the 7602 count, but showing all blank)
Any ideas why its showing blanks?
Events in the event viewer will generally be blank unless they include a _raw field. Your sv file probably does not have a field (or column) called _raw, which is the text of the event.
jrodman, how do you designate the _raw field?
Y