Hey everyone. I am trying to input .csv files. The issue with the files is that the software generating them includes the timestamp numerous times in each line. Here's a rough example:
You get the idea. I don't want to waste space indexing all of the extra timestamp fields. Any advice?
asked 03 Feb '11, 17:25
You can use an index time TRANSFORM, or more likely a SEDCMD to modify the data before it goes into the index: http://www.splunk.com/base/Documentation/4.1.6/Admin/Anonymizedatawithsed
answered 03 Feb '11, 20:41