Splunk cannot read csv updated by lookupeditor correctly.
For example, in the following cases, Splunk cannot read correctly.
1. Pressed the Save button without changing the contents
2. Added a row at the bottom of csv file
However, Splunk can be read correctly in the following cases.
1. Pressed the Save button with changing the contents
2. Added a row between rows of csv file
Does anyone have a similar problem?
Any help will be greatly appreciated.
Regards,
Kagiyama
What error message(s) do you get?
Have you tried a different version of Lookup File Editor?
Thank you for your response.
I checked the index(internal or audit) and found no errors.
It does not occur in different versions of Lookup File Editor or different environments.
The following is a file generation image.
In all cases the contents of all files are correct.
-rw------- 1 splunk splunk 326 10:20 xxx.csv
-rw------- 1 splunk splunk 284 10:10
Press the Save at 10:30
-rw------- 1 splunk splunk 326 10:30 xxx.csv
-rw------- 1 splunk splunk 284 10:10
-rw------- 1 splunk splunk 284 10:20
However, splunk may not be able to read these files correctly when importing them.
Which version of splunk?
Version is 7.1.2 .