...ollowing:
06/01/2017 09:23:45 server1 I am broken Unknown Unknown
06/01/2017 10:11:34 server2 I am not well Unknown Unknown
It looks like the Time-based...
I have a CSV lookup table with a field that contains latest_event and the value is in format "12/25/2019 12:10" (%m/%d/%Y %H:%M) and the time zone is CST. I am comparing latest_event filed with s...
I'm trying to configureatime-basedlookup (temporal lookup) but it doesn't seem to be working as expected. Any advice would be great. Thanks! I'm using the Expiration field to configuretime-based...
...MI:WinEventLog:Security" | lookupactiveusers user (based on: http://stratumsecurity.com/2012/07/03/splunk-security/)
I also tried:
| inputlookup users.csv | search search sourcetype="W...
In alookup file, how can I configure more than one time-based fields (ex. start_date , update_date , expire_date )?
Within this doc for configuring field lookups it appears to say that only o...
Hi, I'm trying to configureatime-basedlookup (temporal lookup) but it doesn't seem to be working as expected. 1) The lookup definitions fields are: time, context, tag::timebased time...
...ommand, it generates two warnings "Script for lookup table 'LOOKUP NAME' returned error code 47. Results may be incorrect." And the same with error code 1.
Based on other threads here, I tried r...
...s time-based. Once you've defined the lookup table, you can invoke the lookup in a search (using the lookup command) or you can configure the lookup to occur automatically.
...tamp for that date. I'd like to do this to save space on my indexer since I have limited resources to use.
I initially created a csv basedlookup file with a search that pulled the _time and app v...
...poch time fields? The epoch time is the time when the value is registered. i know what there is exist that " Configuretime-basedlookup" on lookup table. Can I use this to configure ttl? I w...