We have a need to use the vertical bar (ie "|") as a delimiter. Splunk DB Connect uses a comma. I tried searching for a config parameter but was unsuccessful.
There is currently no way to change the delimiter for the CSV output format of database inputs. But there is an alternative. It requires a little more work to set it up, tough.
You can select the "Template" output format which allows you to specify an arbitrary format you can define by using "replacement tokens". For example:
$timestamp$|$COLUMN1$|$COLUMN2$|$COLUMN3$
DB Connect then replaces those tokens $<COLUMN NAME>$
with the actual content from this column.
There is currently no way to change the delimiter for the CSV output format of database inputs. But there is an alternative. It requires a little more work to set it up, tough.
You can select the "Template" output format which allows you to specify an arbitrary format you can define by using "replacement tokens". For example:
$timestamp$|$COLUMN1$|$COLUMN2$|$COLUMN3$
DB Connect then replaces those tokens $<COLUMN NAME>$
with the actual content from this column.
That is correct. I should have mentioned delimiters for database inputs 🙂
Which delimiter is it, that you want to change? The format of events generated by database inputs?