Splunk Search

Need Help With Lookup returning multiple values

katzr
Path Finder

So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup (example: identifier=rachel date=10/24 description=AB and also another record with identifier=rachel date=10/24 description=AC). I am pulling this information in based on matching on my identifier.

The problem is I only want to include information from 21 days on, but my function below is not working because there are multiple dates for each identifier. But I do want to include information from both descriptions for Rachel. How can I edit my search so that only records from 21 days ago are included but still includes multiple description information for my identifier. Let me know if you need any more information!

| eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma

kyaparla
Path Finder

After lookup, expand you date field, using mvexpand command, and do your strptime & where functions.

|mvexpand date | eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, August edition

In the dynamic world of cybersecurity, staying ahead means constantly solving new puzzles and optimizing your ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Whether you're managing complex deployments or looking to future-proof your data infrastructure, this session ...