Hi,
I am getting the below message when I am using lookup
my command .... | lookup "Full_CDI.csv" user_sso
Empty csv lookup file (contains only a header) for table 'Full_CDI.csv': C:\Program Files\Splunk\etc\apps\search\lookups\Full_CDI.csv
I have around 5,91,662 Data in my Full_CDI.csv file, but still I am not getting any data as a output , all the fileds are coming blank in the result set in SPLUNK but data is present in the CSV file..
Suggest me any solution for this !!
Thanks in Advance !!
What does the output look like if you run:
| inputlookup "Full_CDI.csv"
Make sure the csv is in UTF-8 and not ANSI, and is not just a poorly formatted excel document.
Hope this helps.
when I am seperately doing the below command :
|inputlookup "Full_CDI.csv"
then all the data I am getting as my result set
Please suggest !!