Hi all,
I'm trying to use INDEXED_EXTRACTIONS = CSV but for some reason it's just not working. My input looks as follows
***SPLUNK*** sourcetype=csv source=index/host/query.sql
"SESSION_ID","LOGON_TIME","SCHEMA_NAME","TOTAL_SESSION_MEMORY"
"119","2014-08-22 11:04:03","SYS","813704"
and my props.conf
[csv]
DATETIME_CONFIG=NONE
INDEXED_EXTRACTIONS=CSV
TRANSFORMS-index=index-as-first-folder
None of the four fields are extracted, but the TRANSFORMS as well as the DATETIME_CONFIG take effect. Can anybody spot a mistake?
... View more