I have a lookup table like in splunk this:
earliest_time | latest_time | S_NO | SRC_IP |
3/1/2021 | 4/1/2021 | E1002 | 10.10.10.10 |
I want to exclude the SRC_IP within time(earliest_time and latest_time) from the search.
How could I write the splunk sql to implement this?
Try something like this
your search
| lookup lookup-table-name IP OUTPUT earliest_time latest_time
| eval earliest_time=strptime(earliest_time,"%m/%d/%Y)
| eval latest_time=strptime(latest_time,"%m/%d/%Y)
| where _time < earliest_time OR _time > latest_time
Try something like this
your search
| lookup lookup-table-name IP OUTPUT earliest_time latest_time
| eval earliest_time=strptime(earliest_time,"%m/%d/%Y)
| eval latest_time=strptime(latest_time,"%m/%d/%Y)
| where _time < earliest_time OR _time > latest_time