I need to keep the name of all systems that have been detected for phishing in order to use it in another search,
so I update my lookup table with scheduled search as follow:
inputlookup phishing.csv | append [look for phishing logs]| outputlookup phishing.csv
I used append command to keep the previous rows, but I just need to keep each raw only for 1 week from the time it has been added to table (I mean give the time to live=1h)
Try like this. This will add a column called
addedtime to all rows with the time they were added (using scheduled search). The where filter will remove rows older than 1 week from now.
inputlookup phishing.csv | append [look for phishing logs ] | eval addedtime=coalesce(addedtime,now()) | where addedtime>relative_time(now(),"-1w") | outputlookup phishing.csv