Hi Everyone, Below is my CSV fields and some values and I am doing continuous monitoring CSV file: TIMESTAMP, NAME, AGE, PHONE_NO, ZIP 07/08/2020 12:00:00 PM, ABC, 20, XYZ, 123 07/07/2020 12:00:00 PM, XYZ, 18, XYZ, 456 1. Splunk stores as 3 event, as Splunk is also considering field names as a event.. which I do not want to index fieldname as a event. I have tried several Splunk Answers but no luck or might be I am doing in a wrong way. Please suggest how to fix this. 2. TIMESTAMP, NAME, AGE, PHONE_NO, ZIP 07/08/2020 12:00:00 PM, ABC, 20, XYZ, 123 07/08/2020 12:00:00 PM, PQR, 19, XYZ, 456 I have changed in 2nd row for NAME & AGE and modified Time so that Splunk can pick that latest time and display latest data on dashboard.. So problem is everytime saving excel, Splunk indexing all the data inside the excel including field name.. I do not want to index field names as a event and Splunk index only data for new entries or for those entries which I have make the changes to avoid duplicate data indexing again and again. It would be good if anyone can help me out to fix this issue. Thanks!
... View more