Splunk Search

Should the records in time-based lookup csv file must to be sequence (order) by time?

leo_wang
Path Finder

Hi,

I have done some test using small set of data in my lab.
It looks like the time-based lookup work correct when the records in csv file are not order by time.

But I am curious that if the lookup table is large ( about 1~2 GB ) , is it still working correct ?
Anyone has the experience ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...