I have a lookup file that is recreated daily and the last field is the current date.
item id 2015-03-08
item1 1
item2 2
item3 3
When doing a lookup the date field name does not match the current date value in the csv. It is an older date.
Example :
| inputlookup my_lookup
item id 2015-02-28
item1 1
item2 2
item3 3
Previously, I would get whatever date field was in the csv. When I check the lookup definitions the supported fields are listed as item, id, 2015-02-28
. How can I have Splunk return the current date field name in the csv and not the old field name?
I agree that having a date field with date value would be ideal, but this is how the file is currently provided. After further investigation, it seems that Splunk was moved to a new directory on the server because of space constraints and the path was set to the old directory. Thanks for your help anyways!
I agree that having a date field with date value would be ideal, but this is how the file is currently provided. After further investigation, it seems that Splunk was moved to a new directory on the server because of space constraints and the path was set to the old directory. Thanks for your help anyways!
Have you considered adding a field date
that has the date as a value? Should be much easier to work with later if the field name doesn't change all the time. Also, having the minus operator in a field name can lead to unexpected results.