hi! Working on adding a holiday table as a lookup to reference for alerts based on volume and want to alert on different thresholds if its a holiday. the referenced search is showing data for 7/1...
See more...
hi! Working on adding a holiday table as a lookup to reference for alerts based on volume and want to alert on different thresholds if its a holiday. the referenced search is showing data for 7/10 as nonHoliday, even though for a test, i have it listed as a holiday in the lookup file. its a .csv, so no initial formatting seems to be passing thru the file, need to format the holidayDate column in mm/dd/yyyy index=my_index
| eval eventDate=strftime(_time, "%m/%d/%Y")
| lookup holidayLookup.csv holidayDate as eventDate OUTPUT holidayDate
| eval dateLookup = strftime(holidayDate, "%m/%d/%Y")
| eval holidayCheck=if(eventDate == dateLookup, "holiday", "nonHoliday")
| fields eventDate holidayCheck
| where holidayCheck="nonHoliday" screen shot shows its captured the event date as expected and is outputting a value for holidayCheck, but, based on the data file its referencing, it should show as Holiday. data structure holidayDate holidayName 07/10/2024 Testing Day 07/04/2024 Independence Day