<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Timestamp for values in a lookup table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437983#M124702</link>
    <description>&lt;P&gt;Is there any way I can find out when was a particular value entered into a Lookup table? My search query depends on the date values was created/entered in a lookup table.&lt;BR /&gt;
Thanks in advance. &lt;/P&gt;</description>
    <pubDate>Thu, 02 May 2019 19:43:07 GMT</pubDate>
    <dc:creator>kiranpatil1985</dc:creator>
    <dc:date>2019-05-02T19:43:07Z</dc:date>
    <item>
      <title>Timestamp for values in a lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437983#M124702</link>
      <description>&lt;P&gt;Is there any way I can find out when was a particular value entered into a Lookup table? My search query depends on the date values was created/entered in a lookup table.&lt;BR /&gt;
Thanks in advance. &lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 19:43:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437983#M124702</guid>
      <dc:creator>kiranpatil1985</dc:creator>
      <dc:date>2019-05-02T19:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp for values in a lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437984#M124703</link>
      <description>&lt;P&gt;If your lookup table values doesn't contain the timestamp itself, you won't be able to know when an entry was entered. A lookup is a static csv file (assuming it's a file based lookup), and it has no historical reference to previous state.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 21:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437984#M124703</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-05-02T21:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Timestamp for values in a lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437985#M124704</link>
      <description>&lt;P&gt;Not unless it was included when the event was written.  It is &lt;EM&gt;possible&lt;/EM&gt;, though, that the &lt;CODE&gt;_raw&lt;/CODE&gt; field was accidentally included in the file but you will not see it unless you do &lt;CODE&gt;| rename _* AS invisible_*&lt;/CODE&gt; and if you have that, you can probably find the timestamp inside of the raw event.&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 20:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Timestamp-for-values-in-a-lookup-table/m-p/437985#M124704</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-04T20:09:33Z</dc:date>
    </item>
  </channel>
</rss>

