I have a CSV file that has the following header:
ColumnName1, ColumnName2, Date1, Date2, Date3, Date4, Date5, Date6, and so on......
The first two columns describe my data and the rest of the columns consist of values for each of the different dates. Is there a way to get splunk to use the date columns as a timestamp for all of the values in each column?
In Splunk 6, you can choose one of the Date columns to use as the timestamp.
http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime
TIMESTAMP_FIELDS = Date1