I need to keep the name of all systems that have been detected for phishing in order to use it in another search,
so I update my lookup table with scheduled search as follow:
inputlookup phishing.csv | append [look for phishing logs]| outputlookup phishing.csv
I used append command to keep the previous rows, but I just need to keep each raw only for 1 week from the time it has been added to table (I mean give the time to live=1h)
Any idea?
Try like this. This will add a column called addedtime
to all rows with the time they were added (using scheduled search). The where filter will remove rows older than 1 week from now.
inputlookup phishing.csv | append [look for phishing logs ] | eval addedtime=coalesce(addedtime,now()) | where addedtime>relative_time(now(),"-1w") | outputlookup phishing.csv
Try like this. This will add a column called addedtime
to all rows with the time they were added (using scheduled search). The where filter will remove rows older than 1 week from now.
inputlookup phishing.csv | append [look for phishing logs ] | eval addedtime=coalesce(addedtime,now()) | where addedtime>relative_time(now(),"-1w") | outputlookup phishing.csv
Great,thx,but then shouldn't we say where addedtime <
Great,thx,but then shouldn't we say where addedtime
I didn't get it. Did portion of your comment got truncated?