Getting Data In

Fields are missing from some of my records after importing a CSV file

ianthebrave
New Member

Hi!

I imported a CSV file with 97 fields and after doing some searches, some fields are missing for some records. I have this so-called 'close_notes' field and it's present to some of the records while there are a few records where it does not exist.

Thank you.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ianthebrave, if cusello answered your question please remember to accept the answer to both close this question and to award karma points. Happy splunking! 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

hi ianthebrave,
check the quality of your csv, sometimes I found in so many fields some construction error.
Try to open it in Excel to examine the row with the missed fields, maybe there's less commas then the others or it's too long.
If you cannot open it, open with an editor and take only few rows, included the ones with missed fields.
Bye.
Giuseppe

Sukisen1981
Champion

I second Giuseppe, look closely at your CSV and splunk events, your events will be separated by a , in the splunk events, it is possible that the data input field from your CSV is having some issues. There is no way that once uploaded, the splunk index misses some while accepting some close_notes field values. Have you checked if the fields in CSV BEFORE this field in your CSV is not blank / empty for some rows in the CSV?

0 Karma

gcusello
SplunkTrust
SplunkTrust

If this answer satisfies your question, please accept or upvote it.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...