Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

inputlookup on CSV - including date ranges in csv - help!

$
0
0
Hi, I'm trying to run this query: index="proxy" [|inputlookup TEST.csv | return 2 $IPs $dates] My TEST.csv file has the following: IPs dates 10.10.10.10 earliest=11/27/2015:10:00:00 latest=11/27/2015:11:00:00 10.10.10.2 earliest=11/26/2015:10:30:00 latest=11/26/2015:11:30:00 I'm getting the following error: Error in 'litsearch' command: Unable to parse the search: Invalid time bounds in search: start=1450255314 > end=1448622000. If I remove the 2 in the search query, so that it's like: index="proxy" [|inputlookup TEST.csv | return $IPs $dates] it only returns the first row in my CSV and doesn't parse the second one. Is there a problem with my CSV - or is there a better way to do this? I have a list of about 150~ entries. Any help would be great. Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>