Background: I attempted to import a CSV file into a KV Store using v3.3.3 of the Lookup Editor app. One of the fields in the CSV uses 0 to represent false and 1 to represent true. I set the corresponding field as Boolean when I created the KV Store but when I tried to import the data the Boolean field showed "#bad-value". I found that in order to get the CSV to be successfully imported into the KV Store, I had to pre-process the script (using sed) to replace the 1's with "true" (sans quotes) and the 0's with false (again, sans quotes).
Various settings within the Splunk config files use 0 to represent false and 1 to represent true. Would it be possible to have Lookup Editor do the same when importing in to a field that has been typed as "Boolean"?
I opened a feature request to implement this: https://lukemurphey.net/issues/2606
I'm currently planning to implement this in the next feature release (3.4).
I opened a feature request to implement this: https://lukemurphey.net/issues/2606
I'm currently planning to implement this in the next feature release (3.4).
Https://ideas.spunk.com and then post link here so we can UpVote
.
Hi @woodcock,
Lookup Editor is developed by a third-party (@LukeMurphey) and I'm of the belief that https://ideas.splunk.com is only for software developed by Splunk.
Good point. I missed the Lookup Editor
part.