<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup within time range in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/534039#M150928</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/164073"&gt;@stephenmeyers&lt;/a&gt;, sorry, I edited my reply, the time field name was wrong. This way lookup will also check the _time of event to be bigger then start_time field in the lookup. Although it will not use the end_time field, it should show your desired result.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2020 10:56:13 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2020-12-24T10:56:13Z</dc:date>
    <item>
      <title>Lookup within time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533986#M150904</link>
      <description>&lt;P&gt;I have data being fed to splunk in real time that I would like to tie to project IDs and budgets in a lookup table based on two criteria:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;time falls between start_time and end_time in&amp;nbsp; the lookup table&lt;/LI&gt;&lt;LI&gt;owner equals the owner in the lookup table&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Here's the example data:&lt;/P&gt;&lt;TABLE border="1" width="99.87096774193549%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;time&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;owner&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Spent&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Notes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-10-26 10:06:00&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Bill&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$30&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Supplies&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-10-26 12:16:41&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Bill&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$10&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Food&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-10-27 06:30:51&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Jeff&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$10&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Food&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-11-04 07:06:03&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Bill&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$15&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-11-04 08:01:19&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Frank&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$20&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-11-05 08:10:00&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Bill&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$20&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Supplies&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="36.25806451612903%"&gt;2020-11-05 08:12:21&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;Jeff&lt;/TD&gt;&lt;TD width="15.870967741935486%"&gt;$10&lt;/TD&gt;&lt;TD width="31.870967741935484%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the example lookup table:&lt;/P&gt;&lt;TABLE border="1" width="99.87096774193549%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="23.741935483870968%"&gt;project_id&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;owner&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;budget&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;start_time&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;end_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="23.741935483870968%"&gt;1e&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;Bill&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;$200&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-10-26 08:00:00&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-04 12:00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="23.741935483870968%"&gt;2b&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;Jeff&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;$200&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-10-21 08:00:00&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-06 12:00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="23.741935483870968%"&gt;4a&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;Frank&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;$100&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-04 08:00:00&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-22 17:00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="23.741935483870968%"&gt;2a&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;Bill&lt;/TD&gt;&lt;TD width="11.870967741935484%"&gt;$200&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-05 08:00:00&lt;/TD&gt;&lt;TD width="26.193548387096776%"&gt;2020-11-10 12:00:00&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the output I am looking for:&lt;/P&gt;&lt;TABLE border="1" width="99.87096774193547%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;time&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;project_id&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;budget&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;owner&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Spent&lt;/TD&gt;&lt;TD width="12%"&gt;Notes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-10-26 10:06:00&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;1e&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$200&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Bill&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$30&lt;/TD&gt;&lt;TD width="12%"&gt;Supplies&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-10-26 12:16:41&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;1e&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$200&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Bill&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$10&lt;/TD&gt;&lt;TD width="12%"&gt;Food&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-10-27 06:30:51&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;2b&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$200&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Jeff&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$10&lt;/TD&gt;&lt;TD width="12%"&gt;Food&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-11-04 07:06:03&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;1e&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$200&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Bill&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$15&lt;/TD&gt;&lt;TD width="12%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-11-04 08:01:19&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;4a&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$100&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Frank&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$20&lt;/TD&gt;&lt;TD width="12%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;&lt;STRONG&gt;2020-11-05 08:10:00&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;&lt;STRONG&gt;2a&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;&lt;STRONG&gt;$200&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;&lt;STRONG&gt;Bill&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;&lt;STRONG&gt;$20&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="12%"&gt;&lt;STRONG&gt;Supplies&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="22.064516129032256%"&gt;2020-11-05 08:12:21&lt;/TD&gt;&lt;TD width="13.93548387096774%"&gt;2b&lt;/TD&gt;&lt;TD width="10.32258064516129%"&gt;$200&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;Jeff&lt;/TD&gt;&lt;TD width="20.774193548387096%"&gt;$10&lt;/TD&gt;&lt;TD width="12%"&gt;Fuel&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not really sure how to use the lookup command on a range, or if it's possible. Any suggestions/solutions are welcome. Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 20:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533986#M150904</guid>
      <dc:creator>stephenmeyers</dc:creator>
      <dc:date>2020-12-23T20:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup within time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533989#M150906</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/164073"&gt;@stephenmeyers&lt;/a&gt;, you should use time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;transforms.conf

[project_lookup]
filename = project_lookup.csv
time_field = start_time
time_format = %Y-%m-%d %H:%M:%S

props.conf

[project_lookup]
LOOKUP-project = project_lookup owner OUTPUT project_id budget&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Configureatime-boundedlookup" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Configureatime-boundedlookup#Defining_time-based_lookups&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 10:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533989#M150906</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-24T10:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup within time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533991#M150907</link>
      <description>&lt;P&gt;It doesn't look like this solution would match by the time within start_time and end_time, but only by the owner field. In the example, owner Bill is on 2 different projects, but the time ranges are different.&lt;/P&gt;&lt;P&gt;The time &lt;EM&gt;range&lt;/EM&gt; bit is the real hurdle I'm dealing with.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 20:09:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/533991#M150907</guid>
      <dc:creator>stephenmeyers</dc:creator>
      <dc:date>2020-12-23T20:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup within time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/534039#M150928</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/164073"&gt;@stephenmeyers&lt;/a&gt;, sorry, I edited my reply, the time field name was wrong. This way lookup will also check the _time of event to be bigger then start_time field in the lookup. Although it will not use the end_time field, it should show your desired result.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 10:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-within-time-range/m-p/534039#M150928</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-24T10:56:13Z</dc:date>
    </item>
  </channel>
</rss>

