<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter Results From Multiple Date Ranges in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618280#M214878</link>
    <description>&lt;P&gt;This looks like a good use case for time based lookups:&lt;/P&gt;&lt;P&gt;1. Create a lookup "exclude_maintenance_window_lookup.csv" with an additional field of excluded=1, for example:&lt;/P&gt;&lt;TABLE width="862"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="32"&gt;type&lt;/TD&gt;&lt;TD width="193"&gt;start&lt;/TD&gt;&lt;TD width="193"&gt;end&lt;/TD&gt;&lt;TD width="55"&gt;deviceID&lt;/TD&gt;&lt;TD width="330"&gt;note&lt;/TD&gt;&lt;TD width="59"&gt;excluded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="32"&gt;time&lt;/TD&gt;&lt;TD width="193"&gt;2022-10-03T13:10:30.000-04:00&lt;/TD&gt;&lt;TD width="193"&gt;2022-10-04T14:10:30.000-04:00&lt;/TD&gt;&lt;TD width="55"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="330"&gt;test range 10-04-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Configure a new lookup definition (use default value for anything not defined below):&lt;BR /&gt;Name: exclude_maintenance_window_lookup&lt;BR /&gt;Type: File-based&lt;BR /&gt;Lookup file: exclude_maintenance_window_lookup.csv&lt;BR /&gt;Configure time-based lookup: Checked&lt;BR /&gt;Name of time field: start&lt;BR /&gt;Time format: %Y-%m-%dT%H:%M:%S.%3N%z&lt;BR /&gt;Minimum offset: 0&lt;BR /&gt;Advanced Options -&amp;gt; Maximum matches: 1&lt;/P&gt;&lt;P&gt;3. To use the lookup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base_search&amp;gt;
| eval excluded=1
| lookup exclude_maintenance_window_lookup excluded OUTPUT start end note
| eval end_time=strptime(end, "%Y-%m-%dT%H:%M:%S.%3N%z")
| eval is_excluded=IF(_time&amp;lt;end_time, "Y", "N")

| search is_excluded="N"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2022 20:20:34 GMT</pubDate>
    <dc:creator>johnhuang</dc:creator>
    <dc:date>2022-10-25T20:20:34Z</dc:date>
    <item>
      <title>How to filter results from multiple date ranges?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618275#M214876</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; I am creating some reports to measure the uptime of hardware we have deployed, and I need a way to filter out multiple date/time ranges the match up with maintenance windows.&amp;nbsp; We are utilizing a Data Model and tstats as the logs span a year or more.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The (truncated) data I have is formatted as so:&lt;/P&gt;
&lt;P&gt;time range: Oct. 3rd - Oct 7th.&lt;BR /&gt;&lt;BR /&gt;|tstats summariesonly=true allow_old_summaries=true count(device.status) as count from datamodel=Devices.device where device.status!="" AND device.customer="*" AND device.device_id ="*" by device.customer, device.device_id, device.name, device.status _time&lt;/P&gt;
&lt;P&gt;device.customer device.device_id device.name device.status _time count&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;offline&lt;/TD&gt;
&lt;TD&gt;2022-10-04&lt;/TD&gt;
&lt;TD&gt;314&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;offline&lt;/TD&gt;
&lt;TD&gt;2022-10-05&lt;/TD&gt;
&lt;TD&gt;782&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;offline&lt;/TD&gt;
&lt;TD&gt;2022-10-06&lt;/TD&gt;
&lt;TD&gt;749&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;offline&lt;/TD&gt;
&lt;TD&gt;2022-10-07&lt;/TD&gt;
&lt;TD&gt;1080&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;online&lt;/TD&gt;
&lt;TD&gt;2022-10-04&lt;/TD&gt;
&lt;TD&gt;510&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;online&lt;/TD&gt;
&lt;TD&gt;2022-10-05&lt;/TD&gt;
&lt;TD&gt;658&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;online&lt;/TD&gt;
&lt;TD&gt;2022-10-06&lt;/TD&gt;
&lt;TD&gt;691&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;online&lt;/TD&gt;
&lt;TD&gt;2022-10-07&lt;/TD&gt;
&lt;TD&gt;360&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;warning&lt;/TD&gt;
&lt;TD&gt;2022-10-04&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;warning&lt;/TD&gt;
&lt;TD&gt;2022-10-06&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ppt&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;Sao Paulo Office&lt;/TD&gt;
&lt;TD&gt;warning&lt;/TD&gt;
&lt;TD&gt;2022-10-07&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the reports will be run by other teams ad hoc, I was attempting to use a 'blacklist' lookup table to allow them to add the devices, time ranges, or device AND time range they wish to exclude from the results.&amp;nbsp; That lookup table is formatted as such:&lt;/P&gt;
&lt;TABLE width="950"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="77"&gt;type&lt;/TD&gt;
&lt;TD width="196"&gt;start&lt;/TD&gt;
&lt;TD width="196"&gt;end&lt;/TD&gt;
&lt;TD width="148"&gt;deviceID&lt;/TD&gt;
&lt;TD width="333"&gt;note&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;time&lt;/TD&gt;
&lt;TD&gt;2022-10-03T13:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;2022-10-04T14:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;test range 10-04-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;device&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12345&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;timedevice&lt;/TD&gt;
&lt;TD&gt;2022-10-04T13:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;2022-10-05T14:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8162&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;time&lt;/TD&gt;
&lt;TD&gt;2022-10-06T13:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;2022-10-06T14:10:30.000-04:00&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;test range 10-06-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;device&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;webOS-205AZXCA8122&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my head, this works as a report they run on the total timeframe they wish to analyze, and then the devices, timeframes, and timeframe/device events are removed as entered on the lookup table.&lt;BR /&gt;&lt;BR /&gt;My biggest hang up right now is finding a way to exclude the unknown quantity of time or timedevice blacklist entries from the total list of results.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for any help you can provide!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618275#M214876</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-25T20:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618280#M214878</link>
      <description>&lt;P&gt;This looks like a good use case for time based lookups:&lt;/P&gt;&lt;P&gt;1. Create a lookup "exclude_maintenance_window_lookup.csv" with an additional field of excluded=1, for example:&lt;/P&gt;&lt;TABLE width="862"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="32"&gt;type&lt;/TD&gt;&lt;TD width="193"&gt;start&lt;/TD&gt;&lt;TD width="193"&gt;end&lt;/TD&gt;&lt;TD width="55"&gt;deviceID&lt;/TD&gt;&lt;TD width="330"&gt;note&lt;/TD&gt;&lt;TD width="59"&gt;excluded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="32"&gt;time&lt;/TD&gt;&lt;TD width="193"&gt;2022-10-03T13:10:30.000-04:00&lt;/TD&gt;&lt;TD width="193"&gt;2022-10-04T14:10:30.000-04:00&lt;/TD&gt;&lt;TD width="55"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="330"&gt;test range 10-04-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Configure a new lookup definition (use default value for anything not defined below):&lt;BR /&gt;Name: exclude_maintenance_window_lookup&lt;BR /&gt;Type: File-based&lt;BR /&gt;Lookup file: exclude_maintenance_window_lookup.csv&lt;BR /&gt;Configure time-based lookup: Checked&lt;BR /&gt;Name of time field: start&lt;BR /&gt;Time format: %Y-%m-%dT%H:%M:%S.%3N%z&lt;BR /&gt;Minimum offset: 0&lt;BR /&gt;Advanced Options -&amp;gt; Maximum matches: 1&lt;/P&gt;&lt;P&gt;3. To use the lookup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;base_search&amp;gt;
| eval excluded=1
| lookup exclude_maintenance_window_lookup excluded OUTPUT start end note
| eval end_time=strptime(end, "%Y-%m-%dT%H:%M:%S.%3N%z")
| eval is_excluded=IF(_time&amp;lt;end_time, "Y", "N")

| search is_excluded="N"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618280#M214878</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-25T20:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618281#M214879</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp;I'll give this a try, thank you for the lead!&amp;nbsp; I'll report back with results.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618281#M214879</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-25T20:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618285#M214882</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp;How 'time sensitive' is this lookup when used with a data model -- as in,&amp;nbsp; If the lookup table is modified, would the results be immediate?&amp;nbsp; Is it correct that when the lookup table is modified, the model would have to be rebuilt to have it include the updated ranges?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:25:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618285#M214882</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-25T20:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618287#M214883</link>
      <description>&lt;P&gt;Yes, the result is immediate as long as you refresh/reload the search. The lookup does not impact or change any data in the datamodel, so no rebuild necessary.&lt;/P&gt;&lt;P&gt;One caveat is that if you're summarizing data, you need to first summarize it at an small enough time interval that matches the granularity of your maintenance window, e.g. if your maintenance window is typically 30 minute block increments, you should set the tstat span=30m, then run the lookup to filter result, and then run stats to summarize by day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats span=1h summariesonly=true allow_old_summaries=true count(device.status) as count from datamodel=Devices.device where device.status!="" AND device.customer="*" AND device.device_id ="*" by device.customer, device.device_id, device.name, device.status _time
| eval excluded=1
| lookup exclude_maintenance_window_lookup excluded OUTPUT end
| eval end_time=strptime(end, "%Y-%m-%dT%H:%M:%S.%3N%z")
| where _time&amp;lt;end_time
| bucket _time span=1d
| rename device.customer AS device_customer device.device_id AS device_id device.name AS device_name device.status AS device_status
| stats sum(count) AS count BY _time device_customer device_id device_name device_status &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618287#M214883</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-25T20:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618288#M214884</link>
      <description>&lt;P&gt;Thank you, that sounds great.&amp;nbsp; I'll proceed with that testing now.&amp;nbsp; Much appreciated!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618288#M214884</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-25T20:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618433#M214938</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp;It doesn't appear to be evaluating the is_excluded field properly.&amp;nbsp; Could it be related to the end_time field becoming multi value after the lookup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to confirm, here is the setup I have based on your instructions:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Search:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;|tstats summariesonly=true allow_old_summaries=true count(device.status) as count from datamodel=Devices.device where device.status!="" AND device.customer="*" AND device.device_id ="*" by device.customer, device.device_id, device.name, device.status _time span=30m&lt;BR /&gt;|eval excluded=1&lt;BR /&gt;|lookup Historical_Uptime_Blacklist.csv excluded OUTPUT start end note&lt;BR /&gt;| eval end_time=strptime(end, "%Y-%m-%dT%H:%M:%S.%3N%z")&lt;BR /&gt;| eval epoch1=_time&lt;BR /&gt;| eval is_excluded=IF(_time&amp;lt;end_time, "Y", "N")&lt;BR /&gt;| search is_excluded="*"&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Lookup Table:&lt;/STRONG&gt;&amp;nbsp;Historical_Uptime_Blacklist.csv&lt;/P&gt;&lt;TABLE width="529"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="77"&gt;type&lt;/TD&gt;&lt;TD width="64"&gt;start&lt;/TD&gt;&lt;TD width="196"&gt;end&lt;/TD&gt;&lt;TD width="64"&gt;device&lt;/TD&gt;&lt;TD width="64"&gt;excluded&lt;/TD&gt;&lt;TD width="64"&gt;note&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;time&lt;/TD&gt;&lt;TD&gt;2022-10-04T13:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;2022-10-04T14:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;test range 10-04-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;device&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;1234&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;timedevice&lt;/TD&gt;&lt;TD&gt;2022-10-04T13:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;2022-10-04T14:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;1234&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;time&lt;/TD&gt;&lt;TD&gt;2022-10-05T13:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;2022-10-06T14:10:30.000-04:00&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;test range 10-06-2022 1:30 through 2:10 in EST UTC-4&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;device&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;00-10-7f-75-bf-b4_-1&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;DSG 'MTR-CP-B510' Test&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Lookup Definition:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DGaitherAtRoot_0-1666801583405.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22159iDD4FD8E297BCA8DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DGaitherAtRoot_0-1666801583405.png" alt="DGaitherAtRoot_0-1666801583405.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And lastly here is some sample data that I believe displays the issue.&amp;nbsp; Based on the search, I would have expected that first entry to have been is_excluded=Y&amp;nbsp; (Pasted as CSV due to the forum detecting HTML and reformatting the table.)&lt;/P&gt;&lt;P&gt;device.customer,device.device_id,device.name,device.status,_time,count,end,end_time,epoch1,excluded,is_excluded&lt;BR /&gt;RootIntegration,00-10-7f-de-0f-12_-1,TSW-1060-00107FDE0F12,Online,10/4/2022 0:00,20,2022-10-04T14:10:30.000-04:00,1664907030,1664856000,1,N&lt;BR /&gt;,,,,,,2022-10-04T14:10:30.000-04:00,1664907030,,,&lt;BR /&gt;,,,,,,2022-10-06T14:10:30.000-04:00,1665079830,,,&lt;BR /&gt;RootIntegration,00-10-7f-de-0f-12_-1,TSW-1060-00107FDE0F12,Online,10/4/2022 0:30,23,2022-10-04T14:10:30.000-04:00,1664907030,1664857800,1,N&lt;BR /&gt;,,,,,,2022-10-04T14:10:30.000-04:00,1664907030,,,&lt;BR /&gt;,,,,,,2022-10-06T14:10:30.000-04:00,1665079830,,,&lt;BR /&gt;RootIntegration,00-10-7f-de-0f-12_-1,TSW-1060-00107FDE0F12,Online,10/4/2022 1:00,21,2022-10-04T14:10:30.000-04:00,1664907030,1664859600,1,N&lt;BR /&gt;,,,,,,2022-10-04T14:10:30.000-04:00,1664907030,,,&lt;BR /&gt;,,,,,,2022-10-06T14:10:30.000-04:00,1665079830,,,&lt;BR /&gt;RootIntegration,00-10-7f-de-0f-12_-1,TSW-1060-00107FDE0F12,Online,10/4/2022 1:30,22,2022-10-04T14:10:30.000-04:00,1664907030,1664861400,1,N&lt;BR /&gt;,,,,,,2022-10-04T14:10:30.000-04:00,1664907030,,,&lt;BR /&gt;,,,,,,2022-10-06T14:10:30.000-04:00,1665079830,,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DGaitherAtRoot_0-1666801363965.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22158i2D9B89C535E16260/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DGaitherAtRoot_0-1666801363965.png" alt="DGaitherAtRoot_0-1666801363965.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your assistance with this!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618433#M214938</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-26T16:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618437#M214941</link>
      <description>&lt;P&gt;You're referencing the csv file for the lookup instead of the the lookup definition.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;| lookup Historical_Uptime_Blacklist&lt;STRONG&gt;.csv&lt;/STRONG&gt; excluded OUTPUT start end note&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Make sure you run it against the "Name" you defined in the lookup definition rather than the csv file name. For example, if you named it&amp;nbsp;&lt;SPAN&gt;Historical_Uptime_Blacklist:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;| lookup Historical_Uptime_Blacklist&amp;nbsp;excluded OUTPUT start end note&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618437#M214941</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-10-26T16:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618440#M214944</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":sad_but_relieved_face:"&gt;😥&lt;/span&gt;&amp;nbsp; Exactly why I posted so much detail.&amp;nbsp; stupid human error, great catch!&amp;nbsp; Initial results look promising, I'm testing this more in depth now.&amp;nbsp; Thank you so much!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618440#M214944</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-26T16:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Filter Results From Multiple Date Ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618457#M214955</link>
      <description>&lt;P&gt;This looks like it is working as expected.&amp;nbsp; I have more testing to do to verify it fully,&amp;nbsp; but this seems to be a great solution.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 19:37:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-filter-results-from-multiple-date-ranges/m-p/618457#M214955</guid>
      <dc:creator>DGaitherAtRoot</dc:creator>
      <dc:date>2022-10-26T19:37:22Z</dc:date>
    </item>
  </channel>
</rss>

