Getting Data In

Fields are missing from some of my records after importing a CSV file

ianthebrave
New Member

Hi!

I imported a CSV file with 97 fields and after doing some searches, some fields are missing for some records. I have this so-called 'close_notes' field and it's present to some of the records while there are a few records where it does not exist.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ianthebrave, if cusello answered your question please remember to accept the answer to both close this question and to award karma points. Happy splunking! 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

Sukisen1981
Champion

I second Giuseppe, look closely at your CSV and splunk events, your events will be separated by a , in the splunk events, it is possible that the data input field from your CSV is having some issues. There is no way that once uploaded, the splunk index misses some while accepting some close_notes field values. Have you checked if the fields in CSV BEFORE this field in your CSV is not blank / empty for some rows in the CSV?

0 Karma

gcusello
SplunkTrust
SplunkTrust

If this answer satisfies your question, please accept or upvote it.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...