Hello Splunkers!
I have a CSV that I can have loaded into Splunk. Unfortunately, all of my data has been loaded into the "Statistics" tab, rather than the "Events" tab.
Is there a way to force Splunk to load my data as Events?
Thank you.
If you are using inputcsv
or inputlookup
, then no, you cannot. You can however use "Add data" or oneshot
to send it in as events. IMHO, any set of data that does not have a timestamp inside of it should be a lookup, NOT an event.
If you are using inputcsv
or inputlookup
, then no, you cannot. You can however use "Add data" or oneshot
to send it in as events. IMHO, any set of data that does not have a timestamp inside of it should be a lookup, NOT an event.