...ollowing:
06/01/2017 09:23:45 server1 I am broken Unknown Unknown
06/01/2017 10:11:34 server2 I am not well Unknown Unknown
It looks like the Time-based...
I'm trying to configureatime-basedlookup (temporal lookup) but it doesn't seem to be working as expected. Any advice would be great. Thanks! I'm using the Expiration field to configuretime-based...
I have a CSV lookup table with a field that contains latest_event and the value is in format "12/25/2019 12:10" (%m/%d/%Y %H:%M) and the time zone is CST. I am comparing latest_event filed with s...
...hem that their respective shift roster is not configured properly. Can anybody help me out as to how I can proceed in this. The employee_shift_roster.csv looks something like this: Start time...
...MI:WinEventLog:Security" | lookupactiveusers user (based on: http://stratumsecurity.com/2012/07/03/splunk-security/)
I also tried:
| inputlookup users.csv | search search sourcetype="W...
In alookup file, how can I configure more than one time-based fields (ex. start_date , update_date , expire_date )?
Within this doc for configuring field lookups it appears to say that only o...
Hi, I'm trying to configureatime-basedlookup (temporal lookup) but it doesn't seem to be working as expected. 1) The lookup definitions fields are: time, context, tag::timebased time...
Hello Splunk experts,
I would like to simplify some complex SPL queries that search for certain events and apply tags to them according to various business rules based on both keyword searching a...
...ommand, it generates two warnings "Script for lookup table 'LOOKUP NAME' returned error code 47. Results may be incorrect." And the same with error code 1.
Based on other threads here, I tried r...
...tamp for that date. I'd like to do this to save space on my indexer since I have limited resources to use.
I initially created a csv basedlookup file with a search that pulled the _time and app v...