Splunk Search

Remove the first line of CSV to index in splunk

Mayanakhan
Explorer

I have a CSV file which first row contains the hear fields and remaining rows contains values as below. 

name,application,targeturl,type
ABC,Desktop,google.com,chrome
XYZ,IOS,facebook.com,App
GHI,Andriod,twitter.com,App
KLM,Desktop,gmail.com,firefox

 I have added props.conf as below.

[pp_appeaser]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=csv
HEADER_FIELD_ACCEPTABLE_SPECIAL_CHARACTERS=_
KV_MODE=none
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=false
category=Structured
description=Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled=false
pulldown_type=true

 

In search the header fields are getting as fields and as well as values as below.  also i have tried CHECK_FOR_HEADER" and "HEADER_FIELD_LINE_NUMBER=1" stanzas but i have same results.  

Mayanakhan_0-1603900804912.png

 

Can you please suggest how can i resolve this issue, so the name of headers should not index as values. 

 

Labels (1)
0 Karma

Azeemering
Builder

HEADER_FIELD_LINE_NUMBER=2 ?

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...