Splunk Search

Lookup filter based on time

riqbal47010
Path Finder

Hi Everyone,

I have subnet of IP's. whenever we see any traffic from that IP's we need alert but in between we have only few serves which is authorized for next one week(or mentioned time in lookup). I have a lookup table for that having two fields 
src====== date

a.b.c.d----- epoc time(11-12-2020)

 

Now I want a end result that 

any IP from that subnet(UAT Subnet) and  authorized servers access internet even after mentioned date in lookup table.

(Please note that that authorized servers are also from that UAT subnet)

create an alert.

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...