I have a lookup table like in splunk this:
I want to exclude the SRC_IP within time(earliest_time and latest_time) from the search.
How could I write the splunk sql to implement this?
Try something like this
| lookup lookup-table-name IP OUTPUT earliest_time latest_time
| eval earliest_time=strptime(earliest_time,"%m/%d/%Y)
| eval latest_time=strptime(latest_time,"%m/%d/%Y)
| where _time < earliest_time OR _time > latest_time
View solution in original post