I have a CSV file I've loaded two fields are called %CPU and %MEM. Splunk doesn't seem to recognize either field. Are these illegal field names? Also is there another way to refer to filed names such as
Silly noob question this was. I was recreating the special characters in the transforms but splunk doesn't care what the field name is. I changed the fieldnames in transforms.conf to something else (anything else) and it worked
Silly noob question this was. I was recreating the special characters in the transforms but splunk doesn't care what the field name is. I changed the fieldnames in transforms.conf to something else (anything else) and it worked