Is there any way I can find out when was a particular value entered into a Lookup table? My search query depends on the date values was created/entered in a lookup table.
Thanks in advance.
Not unless it was included when the event was written. It is possible, though, that the _raw
field was accidentally included in the file but you will not see it unless you do | rename _* AS invisible_*
and if you have that, you can probably find the timestamp inside of the raw event.
If your lookup table values doesn't contain the timestamp itself, you won't be able to know when an entry was entered. A lookup is a static csv file (assuming it's a file based lookup), and it has no historical reference to previous state.