<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we schedule Splunk to monitor a lookup? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-we-schedule-Splunk-to-monitor-a-lookup/m-p/269268#M80992</link>
    <description>&lt;P&gt;maybe, check time-based lookup... &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourevents"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourevents&lt;/A&gt;&lt;BR /&gt;
&lt;STRONG&gt;Configure a time-based lookup&lt;/STRONG&gt;&lt;BR /&gt;
File-based and external lookups can also be time-based (or temporal), if the field matching depends on time information (a field in the lookup table that represents the timestamp).&lt;/P&gt;

&lt;P&gt;To Configure a time-based lookup, select Configure time-based lookup, then specify the Name of the time field. You can also specify a strptime format for this time information and offsets for the time matching.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2016 09:13:22 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2016-10-24T09:13:22Z</dc:date>
    <item>
      <title>Can we schedule Splunk to monitor a lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-schedule-Splunk-to-monitor-a-lookup/m-p/269267#M80991</link>
      <description>&lt;P&gt;Can we schedule Splunk to monitor a lookup? I have 1 CSV file and that CSV file will be recreated everyday (not updated but totally recreated). i need the new data and compare the data  to one of my index. How do i do this? Creating an index would not be good idea as there are 23 CSVs and moreover comparing 2 indexes is quite complicated. Any ideas how to solve this?&lt;/P&gt;

&lt;P&gt;please ask  if you need more info.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 08:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-schedule-Splunk-to-monitor-a-lookup/m-p/269267#M80991</guid>
      <dc:creator>ivar9692</dc:creator>
      <dc:date>2016-10-24T08:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can we schedule Splunk to monitor a lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-we-schedule-Splunk-to-monitor-a-lookup/m-p/269268#M80992</link>
      <description>&lt;P&gt;maybe, check time-based lookup... &lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourevents"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Usefieldlookupstoaddinformationtoyourevents&lt;/A&gt;&lt;BR /&gt;
&lt;STRONG&gt;Configure a time-based lookup&lt;/STRONG&gt;&lt;BR /&gt;
File-based and external lookups can also be time-based (or temporal), if the field matching depends on time information (a field in the lookup table that represents the timestamp).&lt;/P&gt;

&lt;P&gt;To Configure a time-based lookup, select Configure time-based lookup, then specify the Name of the time field. You can also specify a strptime format for this time information and offsets for the time matching.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 09:13:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-we-schedule-Splunk-to-monitor-a-lookup/m-p/269268#M80992</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2016-10-24T09:13:22Z</dc:date>
    </item>
  </channel>
</rss>

