Hi guys,
I've roamed the prestigious documents of splunk on how to go about this but I am stumped and can't find any guidance. Just as the question states, I am trying to upload a csv file into splunk, without having to go on the physical splunk server and moving it in. Is this possible?
Thanks in advance for your help
This is a common problem when converting an Excel file to CSV. Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.
This is a common problem when converting an Excel file to CSV. Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.
Try using the Lookup Editor app. It provides an interface for uploading lookup files and it will even correct incompatible line endings.
To upload a file, do the following:
Can you access the Splunk UI from the server where the file is? Then you could just go to Settings > Add Data, then drag and drop the file.
Thanks for your response.
So i went to Settings > look ups > look up table files and when I tried to add my csv file I get an error message saying : Encountered the following error while trying to save: In handler 'lookup-table-files': File has no line endings.
Any idea on how to successfully upload it?
There might be some problem in the file, which you are trying to upload, this is a common problem when converting an Excel file to CSV.
Try saving it as Windows Comma Separated Value (.csv), then you should be able to successfully upload the lookup.
There are also some edge cases where if the csv column names have more than 4094 bytes characters Splunk will throw this error.
The solution in my case was to pre-process the csv and truncate the column names.