Because you're using INDEXED_EXTRACTIONS for this data, splunk will automatically put them in the tsidx file associated with the itcc:snow sourcetype.
Example tstats search against your data:
| tstats count as total from <your_index> groupby _time, Company | timechart sum(total) by Company
If you applied your own field names in the beginning (read: index time) you wouldn't have to do the coalesce or FIELDALIAS calisthenics to get your data to look the way you want. 😉
Example configuration (on forwarder):
[itcc:snow]
INDEXED_EXTRACTIONS = csv
TRUNCATE = 50000
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = Opened
HEADER_FIELD_LINE_NUMBER = 30
FIELD_NAMES = assigned_to, business_service, category, closed_at, closed_by, close_code company ...
... View more