Splunk Search

Lookup filter based on time

riqbal47010
Path Finder

Hi Everyone,

I have subnet of IP's. whenever we see any traffic from that IP's we need alert but in between we have only few serves which is authorized for next one week(or mentioned time in lookup). I have a lookup table for that having two fields 
src====== date

a.b.c.d----- epoc time(11-12-2020)

 

Now I want a end result that 

any IP from that subnet(UAT Subnet) and  authorized servers access internet even after mentioned date in lookup table.

(Please note that that authorized servers are also from that UAT subnet)

create an alert.

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...