Splunk Search

All fields from a lookup.csv file appear except the date field?

Path Finder

All fields from a lookup.csv file appear as available search fields except the date field.

Here is how I defined the start_date field in my lookup.csv file:

'2012-03-12 20:10'

%Y-%m-%d %H:%M

So how can I get this start_date field to appear as a potential field in my searching here?

0 Karma
1 Solution

Path Finder

After looking at the raw .csv of the lookup file I see the dates were formatted differently then I expected.

View solution in original post

0 Karma

Path Finder

After looking at the raw .csv of the lookup file I see the dates were formatted differently then I expected.

View solution in original post

0 Karma

Path Finder

Thanks MarioM. After looking at the raw .csv of the lookup file I see the dates were formatted differently then I expected.

0 Karma

Motivator

can you post an extract of your lookup.csv with the header?