I'm trying to get the time-based functionality to work on a kvstore, but I'm not getting anywhere. I have taken a look at the other posts on this topic, but I can't get it working.
My collections.conf file:
[tracking]
enforceTypes=true
field.dashboard = string
field.idhash = string
field.misc = string
field.time = number
My transforms.conf file:
[tracking]
collection = tracking
external_type = kvstore
fields_list = _key,time,dashboard,misc,idhash
time_field = time
time_format = %s
I am adding records to the kvstore via the API, and I'm writing the time in epoch form (seconds, 10 digits).
I'm mainly following the directions is this post: https://community.splunk.com/t5/Splunk-Search/How-to-get-time-based-lookups-working-with-KV-Store/m-...
It looks like Splunk isn't recognising the time format - when I do a time based search, all the records in the kvstore are returned (| inputlookup tracking).