I want to map headers to the data in the csv to search the fields as key=value pair, the sample log is shared below. please help
,,,Date,Time,Sensor Id a,Reading a,Sensor Id b,Reading b,Sensor Id c,Reading c,Sensor Id d,Reading d
,,,01-Jan-12,0:00:00,T001,170.3,T002,168.7,T003,169.7,T004,171.2
,,,01-Jan-12,00:30:00,T001,170.1,T002,168.5,T003,169.5,T004,171
,,,01-Jan-12,1:00:00,T001,170,T002,168.4,T003,169.4,T004,170.8
,,,01-Jan-12,1:30:00,T001,169.6,T002,168.2,T003,169.3,T004,170.5
You can do this by configuring header-based field extractions:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Extractfieldsfromfileheadersatindextime
You can do this by configuring header-based field extractions:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Extractfieldsfromfileheadersatindextime