Splunk is not displaying the latest time of lookup updated
| rest /servicesNS/-/-/data/lookup-table-files
| search title=*
| table title updated
title updated
test.csv 1969-12-31T18:00:00-06:00
Was this issue ever resolved? I am seeing the same issue in my SplunkCloud environment.
Definitely open a support case.
I suspect that the system clock on the host OS of your Search Head is borked or there is a Splunk bug somewhere. That says that the timestamp on the file is 0
, which should not happen.
Hello @woodcock, I do not see any issue with host OS. Not sure if it is a bug with Splunk, as a similar version of Splunk on the other SH is working fine.
@DMohn, lookup file was generated from outputlookup.
This time normally indicates, that the corresponding CSV hasn't been updated via Splunk at all. (It is the '0' UNIX timestamp value).
This interface will only show update times, if the lookup file is updates by means of Splunk (eg. outputlookup) - not if it is re-uploaded via the OS.
hi @ganji
check your user timezone
@harishalipaka, thanks for replying. User time zone is Default System Timezone and user timezone may not be the issue.