why every input data from TCP/UDP, the field always inputted to the data inside, so the data did have field, caused the field inputted to the data,
so my question is, how to make the first line in csv file became field in splunk,
how to setting this one .???
Check out this docs article:
http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Extractfieldsfromfileheadersatindextime