Splunk Search

Should the records in time-based lookup csv file must to be sequence (order) by time?

leo_systex
Explorer

Hi,
As title.
I have done some test using small set of data in my lab.
It looks like the time-based lookup work correct when the records in csv file is not order by time.

But I am curious that if the lookup table is large ( about 1~2 GB ) , is it still working correct ?
Anyone has the experience ?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...