Reporting

How to remove events from Splunk report as per Lookup(Start/End Time entries)

sharma11031988
Explorer

Hello Team,

We have a requirement to remove exclusion period from 30 day report as per known incidents/CR happening during period to remove out-layers.
I was using Data model to retrieve this entries against mentioned date as per regular expression match (WC = "*"), however if there are multiple entries for the day my events are not removed due to conflict.

EventDate StartTime EndTime
Feb/27/2019(WC) Feb/27/2019 20:00:00 Feb/27/2019 23:00:00

Feb/27/2019(WC) Feb/27/2019 12:00:00 Feb/27/2019 14:00:00

Mar/06/2019(WC) Mar/06/2019 12:00:00 Mar/06/2019 13:00:00

Mar/20/2019(WC) Mar/20/2019 13:00:00 Mar/20/2019 18:30:00

Mar/22/2019(WC) Mar/22/2019 20:00:00 Mar/22/2019 23:00:00

Mar/24/2019(WC) Mar/24/2019 11:01:22 Mar/24/2019 11:57:48

Mar/21/2019(WC) Mar/21/2019 10:40:28 Mar/21/2019 11:03:32

Mar/07/2019(WC) Mar/07/2019 08:11:55 Mar/07/2019 08:26:33

Is there a better way of removing this events period from my report, i don't want to delete them as this period may be used if need be.

Thanks,

Tags (2)
0 Karma

sharma11031988
Explorer

I was able to use something from blog : https://answers.splunk.com/answers/659389/how-to-exclude-multiple-time-ranges-from-multiple.html. and use this code to remove events:

if(([| inputlookup exclusion.csv | convert timeformat="%b/%d/%Y %H:%M:%S" mktime(EndTime) mktime(StartTime) | eval search="_time>=".StartTime." AND _time<=".EndTime | return 500 $search]),"false","true")

however when i enable acceleration on Datamodle - i am getting syntax error for condition put in DM like this.

Error in 'eval' command: The expression is malformed. An unexpected character is reached at '[| inputlookup exclusion.csv | convert timeformat="%b/%d/%Y %H:%M:%S" mktime(EndTime) mktime(StartTime) | eval search="_time>=".StartTime." AND _time<=".EndTime | return 500 $search] ),"false","true")'.

Anyone can help me what am i doing wrong

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...