<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Lookup filter based on time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-filter-based-on-time/m-p/532491#M150429</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have subnet of IP's. whenever we see any traffic from that IP's we need alert but in between we have only few serves which is authorized for next one week(or mentioned time in lookup). I have a lookup table for that having two fields&amp;nbsp;&lt;BR /&gt;src====== date&lt;/P&gt;&lt;P&gt;a.b.c.d----- epoc time(11-12-2020)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want a end result that&amp;nbsp;&lt;/P&gt;&lt;P&gt;any IP from that subnet(UAT Subnet) and&amp;nbsp; authorized servers access internet even after mentioned date in lookup table.&lt;/P&gt;&lt;P&gt;(Please note that that authorized servers are also from that UAT subnet)&lt;/P&gt;&lt;P&gt;create an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 15:44:32 GMT</pubDate>
    <dc:creator>riqbal47010</dc:creator>
    <dc:date>2020-12-09T15:44:32Z</dc:date>
    <item>
      <title>Lookup filter based on time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-filter-based-on-time/m-p/532491#M150429</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have subnet of IP's. whenever we see any traffic from that IP's we need alert but in between we have only few serves which is authorized for next one week(or mentioned time in lookup). I have a lookup table for that having two fields&amp;nbsp;&lt;BR /&gt;src====== date&lt;/P&gt;&lt;P&gt;a.b.c.d----- epoc time(11-12-2020)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want a end result that&amp;nbsp;&lt;/P&gt;&lt;P&gt;any IP from that subnet(UAT Subnet) and&amp;nbsp; authorized servers access internet even after mentioned date in lookup table.&lt;/P&gt;&lt;P&gt;(Please note that that authorized servers are also from that UAT subnet)&lt;/P&gt;&lt;P&gt;create an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 15:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-filter-based-on-time/m-p/532491#M150429</guid>
      <dc:creator>riqbal47010</dc:creator>
      <dc:date>2020-12-09T15:44:32Z</dc:date>
    </item>
  </channel>
</rss>

