I have a lookup file with 3 fields - source, status, timestamp. Timestamp is saved as per below: eval timestamp=strftime(_time,"%d%m%y %H:%M:%S") Sample data: ABC, 1, 20/03/21 04:45:46 ABC, 0, 27/03/21 11:17:31 ABC, 1, 29/03/21 14:33:06 ABC, 0, 01/04/21 12:56:41 Search query I am using is - | inputlookup test.csv | sort -TIMESTAMP result as below: ABC, 1, 29/03/21 14:33:06 ABC, 0, 27/03/21 11:17:31 ABC, 1, 20/03/21 04:45:46 ABC, 0, 01/04/21 12:56:41 and when I use query - |inputlookup test.csv | sort TIMESTAMP ABC, 0, 01/04/21 12:56:41 ABC, 1, 20/03/21 04:45:46 ABC, 0, 27/03/21 11:17:31 ABC, 1, 29/03/21 14:33:06 This is weird because sort is happening just based on date! I am not even able to use eval on TIMESTAMP field(result is always empty). Have tried addinfo, where timestamp>now-xxx with no luck.
... View more