Hi, I am new to Splunk and working with parking records. I am trying to display parking spaces that are currently not in use.
Within my monitored data each record has the following fields:
- the time data was created, which is when the car parked
- permit_expiry, which is a couple of hours after the creation time
- parking_space, which is a number between 1 and 99, that doesn't repeat until the permit_expiry has passed.
I also have a separate lookup table/csv file called parking_lots of all parking_space (1-99), and their respective parking_lot.
This is what I have come up with so far:
sourcetype="parking_log"
| where now() < expiry_time
| lookup parking_lots parking_space
| *display parking_space that don't appear in the above search (1-99)*
I am struggling to understand how to display the parking spaces, as well as use of the now() function.
Many thanks!