Splunk Search

Time-based lookup for KV Store

BernardEAI
Communicator

I'm trying to get the time-based functionality to work on a kvstore, but I'm not getting anywhere. I have taken a look at the other posts on this topic, but I can't get it working. 

My collections.conf file:

[tracking]
enforceTypes=true
field.dashboard = string
field.idhash = string
field.misc = string
field.time = number

My transforms.conf file:

[tracking]
collection = tracking
external_type = kvstore
fields_list = _key,time,dashboard,misc,idhash
time_field = time
time_format = %s

I am adding records to the kvstore via the API, and I'm writing the time in epoch form (seconds, 10 digits).

I'm mainly following the directions is this post: https://community.splunk.com/t5/Splunk-Search/How-to-get-time-based-lookups-working-with-KV-Store/m-... 

It looks like Splunk isn't recognising the time format - when I do a time based search, all the records in the kvstore are returned (| inputlookup tracking).

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...