<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531319#M150092</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;sorry for late reply, the csv file has 15 fields with client ip and date and file references, I can't load it from add data and can only add as lookup, but lookup does not allow me to view it as timestamped events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why can I not load it as add data?&lt;/P&gt;&lt;P&gt;Why can I not view events from lookup?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; a lot for any help.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2020 13:09:18 GMT</pubDate>
    <dc:creator>roderick001</dc:creator>
    <dc:date>2020-11-30T13:09:18Z</dc:date>
    <item>
      <title>Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531193#M150062</link>
      <description>&lt;P&gt;My search is&amp;nbsp;| inputlookup "edgarlog2.csv"&lt;/P&gt;&lt;P&gt;The lookup file has no events attached to it, what is a way to add events from a lookup file whilst viewing it in the main search and reporting app?&lt;/P&gt;&lt;P&gt;Any help would be great, thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 18:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531193#M150062</guid>
      <dc:creator>roderick001</dc:creator>
      <dc:date>2020-11-27T18:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531206#M150064</link>
      <description>&lt;P&gt;What is the content of CSV?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 23:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531206#M150064</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-11-27T23:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531319#M150092</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;sorry for late reply, the csv file has 15 fields with client ip and date and file references, I can't load it from add data and can only add as lookup, but lookup does not allow me to view it as timestamped events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why can I not load it as add data?&lt;/P&gt;&lt;P&gt;Why can I not view events from lookup?&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp; a lot for any help.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 13:09:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531319#M150092</guid>
      <dc:creator>roderick001</dc:creator>
      <dc:date>2020-11-30T13:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531505#M150123</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Inputcsv" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Inputcsv&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;please check permission.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Security/How-to-change-permission/m-p/403043" target="_blank"&gt;https://community.splunk.com/t5/Security/How-to-change-permission/m-p/403043&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 12:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531505#M150123</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-01T12:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup file 3000 entries, need to divide into events, so I can isolate user flow of client ip events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531517#M150126</link>
      <description>&lt;P&gt;Thnaks a lot&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184221"&gt;@to4kawa&lt;/a&gt;&amp;nbsp;, I will look into it and get back to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 13:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-file-3000-entries-need-to-divide-into-events-so-I-can/m-p/531517#M150126</guid>
      <dc:creator>roderick001</dc:creator>
      <dc:date>2020-12-01T13:35:58Z</dc:date>
    </item>
  </channel>
</rss>

