Why is the Splunk Web service not running after an upgrade to 6.2? Learn more »
I've uploaded a few .csv files as lookup tables that have a month-date timestamp column, but I'm not able to get splunk to read that column as a date. I created a lookup definition specifying the time column and input the "%m-%Y" format (ex: 10-2013), but no dice. I had the data in %b-%Y format (ex: Oct-2013) originally, and I've also tried late binding using
| inputlookup building_elec_consumption.csv | eval time=strptime(Month, "%m-%Y") | fields time
but that creates a blank column.
Can't get lookups to work 3 Answers
Large Joins 1 Answer
Question about lookups 1 Answer
Whitelisting using lookups 1 Answer