Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Question index csv with field contain comma

$
0
0

I have issue with index field which contain comma. Below is my csv input

"28650096","2013-12-02 20:30:30","blocked","porn, sexual content","a@a.com","1.1.2.3" "28650093","2013-12-02 20:30:30","allow","search site","b@b.com","2.2.2.4" "28650092","2013-12-02 20:30:30","blocked","gambling","c@c.com","3.3.3.2"

my props.conf [temp-audit] FIELD_DELIMITER = , INDEXED_EXTRACTIONS = csv KV_MODE = none NO_BINARY_CHECK = 1 REPORT-audit = temp-audit-csv SHOULD_LINEMERGE = false pulldown_type = 1

my transforms.conf [temp-audit-csv] DELIMS=", " FIELDS=id,timeStamp,Type,Reason,email,SourceIP

When add data using A file or directory of files it can see three events without problem. But after done adding data when in search when I do "search *" it only return 2 events it seem the first one didn't make it to the search.

Please help thanks


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>