Splunk Search

Need Help With Lookup returning multiple values

katzr
Path Finder

So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup (example: identifier=rachel date=10/24 description=AB and also another record with identifier=rachel date=10/24 description=AC). I am pulling this information in based on matching on my identifier.

The problem is I only want to include information from 21 days on, but my function below is not working because there are multiple dates for each identifier. But I do want to include information from both descriptions for Rachel. How can I edit my search so that only records from 21 days ago are included but still includes multiple description information for my identifier. Let me know if you need any more information!

| eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma

kyaparla
Path Finder

After lookup, expand you date field, using mvexpand command, and do your strptime & where functions.

|mvexpand date | eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...