Getting Data In

How to import more than 50 fields with CSV in Splunk 6?

swilhoi2
New Member

We are having a problem with importing all of our data fields because we are only getting the first 50 fields using version 6.

If someone could help me out with this I would greatly appreciate it.

Thank you,
Seth Wilhoite

Tags (1)
0 Karma

guilmxm
Influencer

Hi,

This is a kv limit in default Splunk configuration.

Edit your $SPLUNK_HOME/etc/system/local/limits.conf and set: (see your default/limits.conf for the full section)

[kv]
# maximum number of keys auto kv can generate
limit    = 50

To a value that would feet your need.

Restart Splunk and re-index your data.

I had the same issue, took me some time to understand and find that 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...