Getting Data In

When indexing an Excel file with the .xlsx file extension, why is the format not showing properly in Splunk?

gyslainlatsa
Motivator

Hello everyone,

I have an Excel file to .xlsx format. When I load it in Splunk, it does not turn around the correct results.
Can someone help me?

Here's how the file is displayed in Excel:

alt text

and when I load it in Splunk, here's how it appears:

alt text

0 Karma

woodcock
Esteemed Legend

You need to pick a subset of the spreadsheet that is straight tabular data with no formulas, strip out everything else, "Save As CSV" and then it will work. The resulting file should have a set of fields separated by commas that is consistent from top to bottom with a field header as the top row. Your stuff is NOTHING like that.

0 Karma

loveforsplunk
Explorer

I think it is because you are not using CSV format. Just change the extension of the excel in .csv and splunk should be able to read the file.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk doesnt support xls formatting as its a proprietary binary (Microsoft) format. If you want to load this in Splunk, save it as a CSV file and upload it into Splunk.

gyslainlatsa
Motivator

hi esix,
thank for your answer but I know, I read in a paper that splunk enterprise Splunk indexes all data types and why you say while splunk does not support the .xlsx extension?

0 Karma

woodcock
Esteemed Legend

All "plain-text" data.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Perhaps you can understand Splunk more by reading the documentation from Splunk as to what we can index :
http://docs.splunk.com/Documentation/Splunk/6.3.1/Data/WhatSplunkcanmonitor

Splunk cant read binary data without preprocessing or converting to human readable text.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...