Splunk Search

import and export date in a file's name

Explorer

Hello,

Is it possible to include the date in the name of an output file ?
example : ... | outputlookup "myname_"+function(date)+".csv"

Is it possible to extract a file .csv with the date of the file ?
example: ... | lookup filename=* date=2013-05-24

Tags (4)
0 Karma

Legend

First question - see this question and answer. http://splunk-base.splunk.com/answers/39974/variable-file-name-in-outputcsv

Not sure exactly what you mean by your second question.

0 Karma

Legend

I think summary indexing might be better suited for solving this problem instead. See http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Usesummaryindexing

0 Karma

Explorer

Thank you,

I search a way to have the average of a colomn not day by day but first day to "current" day for each day (day1 => avg(day1), day2 => avg(day1, day2), day N => avg(day1, ... , dayN).
And then to compare the value of a day with a previous average.

My idea was to save the average and the current date, then to import a previous average througt his date.

0 Karma