I've got a CSV file with a column called "Index." Naturally, this is a bit of a problem. Is there a way to deal with this other than making a new sourcetype for it and specifying the header row? I'd rather not do that because:
I see a field called extracted_index when these files come in, and it appears to have the original value in it, but I can't seem to use it in a search or eval or stats command like I want to. What's up with that?
I am skeptical of your assertion at the end. You definitely should be able use extracted_index
(or extracted_Index
?) That's the whole reason that Splunk creates it!
I am skeptical of your assertion at the end. You definitely should be able use extracted_index
(or extracted_Index
?) That's the whole reason that Splunk creates it!
Ah! Indeed. Victim of my own typo. I had "index" on the brain and thus typed it as such: extracted_index, lowercase. Original field was Index, so it's extracted_Index.
All is right with the world.