Splunk Search

Should the records in time-based lookup csv file must to be sequence (order) by time?


As title.
I have done some test using small set of data in my lab.
It looks like the time-based lookup work correct when the records in csv file is not order by time.

But I am curious that if the lookup table is large ( about 1~2 GB ) , is it still working correct ?
Anyone has the experience ?

0 Karma