I am looking to search for a given value (an IP in this case) between a specific time range. This is easy to do as a one off, but I have a large number of IP’s I need to search for and would ideally like to have a lookup table, with the IP’s and date ranges and for it to be searched for automatically like the below search.csv lookup,
‘src’,’earliest’,’latest’
‘1.1.1.1’, 11/27/2015:10:00:00, 11/27/2015:11:00:00
but it doesn’t seem to be working. Am I doing something wrong? Is there a batter way to do this?
Thanks!
I would drop the latest, and move the earliest field to the first column and rename it to datetime... etc.
Then in props.conf I'd use TIMESTAMP_FIELDS = datetime
http://docs.splunk.com/Documentation/Splunk/6.2.6/Admin/Propsconf
Then I'd index the csv instead of using it as a lookup.
Then you can do things like searching for a specific time frame... and you'll only see events from that time frame with the Ips from that time frame.
You can then do things like | stats min(datetime) by IP .... | timechart max(datetime) by IP ....
I would drop the latest, and move the earliest field to the first column and rename it to datetime... etc.
Then in props.conf I'd use TIMESTAMP_FIELDS = datetime
http://docs.splunk.com/Documentation/Splunk/6.2.6/Admin/Propsconf
Then I'd index the csv instead of using it as a lookup.
Then you can do things like searching for a specific time frame... and you'll only see events from that time frame with the Ips from that time frame.
You can then do things like | stats min(datetime) by IP .... | timechart max(datetime) by IP ....
Any relation to this question? https://answers.splunk.com/answers/334605/inputlookup-on-csv-including-date-ranges-in-csv-he.html
Is this a duplicate question written by a different member of your team?