Splunk Search

Event breaking to middle text at index time

Dov1
Observer

Hello,

I have some text I indexing, In the middle I have csv table, and some information at end, look like this

Text text text text.

#begining of csv#

Aa,BBC,cc,dd

22,1,444,2

44,22,11,3

#end of csv#

Text text text

How to index only the lines in the csv as events

Thank you

Dov

Labels (1)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Unless the csv data is in some distinct easy distinguishable format, there's no way to filter out events based on other events. Events go through ingestion pipeline one at a time and there is no global state you can rely on (to remember whether you already met the header or footer of the data part). With small chunks of this csv data you could try to do some magic involving event breaking so that input is broken on the csv header but it'd be highly ineffective and prone to errors. And you'd get a single event consisting of whole csv content, not separate csv lines and that's probably not what you want.

I'd go for scripted/modular input but that requires some development.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...