<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623267#M14700</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241987"&gt;@sidtalup27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know how you collect Jira data, anyway, instead saving them in a lookup save them in a summary index using the collect command so you'll have progressive events with timestamp, the correlation key and the status, so you can display these indormation in a table.&lt;/P&gt;&lt;P&gt;I cannot be more precise because I don't know how you populate the lookup.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2022 16:05:23 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-12-05T16:05:23Z</dc:date>
    <item>
      <title>How can I capture in the below format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623241#M14694</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are trying to build a dashboard for Incident SLA compliance.&lt;BR /&gt;The data is ingested from JIRA. Tickets are created in JIRA, and Splunk retrieves the information frequently. At this point in time, the concerned fields for me are the Ticket Number and Creation Time. However, when an existing Ticket in JIRA is updated, the new values in Splunk are updated on the existing values. Hence, I lose the previously captured, in this case, I miss out on Creation time, and the same field is updated with New Time. How can I capture in the below format? Please advise.&lt;/P&gt;
&lt;P&gt;Ticket Number, Creation Time, Updated Time.&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;Thanks,&lt;BR /&gt;Siddarth&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 16:40:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623241#M14694</guid>
      <dc:creator>sidtalup27</dc:creator>
      <dc:date>2022-12-05T16:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623243#M14695</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241987"&gt;@sidtalup27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;don't use a lookup to save data extracted from Jira, but a summary index so you have also the timestamp information.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 14:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623243#M14695</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-05T14:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623246#M14696</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;, can you please elaborate? My objective is to create a table of events for a key field, considering INDEX and SOURCETYPE are same.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 14:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623246#M14696</guid>
      <dc:creator>sidtalup27</dc:creator>
      <dc:date>2022-12-05T14:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623267#M14700</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241987"&gt;@sidtalup27&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know how you collect Jira data, anyway, instead saving them in a lookup save them in a summary index using the collect command so you'll have progressive events with timestamp, the correlation key and the status, so you can display these indormation in a table.&lt;/P&gt;&lt;P&gt;I cannot be more precise because I don't know how you populate the lookup.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 16:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-can-I-capture-in-the-below-format/m-p/623267#M14700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-05T16:05:23Z</dc:date>
    </item>
  </channel>
</rss>

