Splunk Search

Lookup filter based on time

riqbal47010
Path Finder

Hi Everyone,

I have subnet of IP's. whenever we see any traffic from that IP's we need alert but in between we have only few serves which is authorized for next one week(or mentioned time in lookup). I have a lookup table for that having two fields 
src====== date

a.b.c.d----- epoc time(11-12-2020)

 

Now I want a end result that 

any IP from that subnet(UAT Subnet) and  authorized servers access internet even after mentioned date in lookup table.

(Please note that that authorized servers are also from that UAT subnet)

create an alert.

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...