I'm facing issue with indexing unstructured text file. Is there any config setting?
Can you please mention some more details, such as the file type, contents of the file and what is the issue you are facing.
Splunk does not face any problem with unstructured data. The only requirement is your data should be in ASCII format. Splunk does not worry about whether the data is structured or not, it just needs to be in ASCII format.
There are some possibilities,
Please write details about your issue and we can help to fix them.
Hi Ashutosh,
I've converted pdf file (unstructured) into text file and indexed same.
Issue I'm facing with extracting fields, I've extracted Patient Name, Provider, Date of Birth, Visit Date, however facing issue with extracting columnar data (table) as below (table may having variable no. of rows).
Dx Code
Diagnosis Code Comment
Other fatigue R53.83
Pruritus, unspecified L29.9
Hi @mukundd,
There are settings in props.conf
for your line breakers and other index time actions. Share your text file with us and we can help you with the indexing issue.
You can find all the settings here :
https://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf
Cheers,
David