Splunk Search

Need Help With Lookup returning multiple values

katzr
Path Finder

So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup (example: identifier=rachel date=10/24 description=AB and also another record with identifier=rachel date=10/24 description=AC). I am pulling this information in based on matching on my identifier.

The problem is I only want to include information from 21 days on, but my function below is not working because there are multiple dates for each identifier. But I do want to include information from both descriptions for Rachel. How can I edit my search so that only records from 21 days ago are included but still includes multiple description information for my identifier. Let me know if you need any more information!

| eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma

kyaparla
Path Finder

After lookup, expand you date field, using mvexpand command, and do your strptime & where functions.

|mvexpand date | eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...