I am monitoring a folder with csv files with 400+ fields, out of which need only 50 fields for my dashboard.
Can we do something in Indexing time, so that it will not index the other 350 fields which are not required.
Removing from CSV is not possible. So, need to handle it in splunk only.
Please suggest.
You can do this with a carefully constructed SEDCMD
setting but this may not work if you are using INDEXED_EXTRACTIONS=csv
(then again, it may very well work). I know that it definitely will work if you are not using INDEXED_EXTRACTIONS
.
Hello,
I don't know if it's working for 400+ fields but I found this post for you : https://answers.splunk.com/answers/529138/filter-csv-logs-before-indexing.html
Ok, I will try this
Let me know if it works