Splunk Search

What does SearchResults "Corrupt csv header" mean?

Lowell
Super Champion

Does anyone know what this message means?

06-14-2010 15:45:14.859 WARN SearchResults - Corrupt csv header, 2 columns with the same name 'ipstr' (col #6 and #2, #6 will be ignored)

0 Karma
1 Solution

Lowell
Super Champion

Think I found the problem. A had a saved search with the following fields search command:

... | fields + user,flags,ipstr,pid,logontime,ipstr,rip,dur_mins,eventcount

Looks like I accidentally listed the "ipstr" field twice. Whoops.

View solution in original post

Lowell
Super Champion

Think I found the problem. A had a saved search with the following fields search command:

... | fields + user,flags,ipstr,pid,logontime,ipstr,rip,dur_mins,eventcount

Looks like I accidentally listed the "ipstr" field twice. Whoops.

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...