Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

KV Store time-based lookups not working in Splunk 6.3.2

$
0
0
Have exactly the same lookups, one in CSV and one in KV Store. The CSV file time-based lookup works perfectly. The KV Store time-based lookup does not. The definitions of the lookups with regards to time-based are exactly the same: time_field = etime time_format = %s.%Q Do time-based lookups from KV store work in 6.3.2?

Viewing all articles
Browse latest Browse all 47296

Trending Articles