So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup (example: identifier=rachel date=10/24 description=AB and also another record with identifier=rachel date=10/24 description=AC). I am pulling this information in based on matching on my identifier.
The problem is I only want to include information from 21 days on, but my function below is not working because there are multiple dates for each identifier. But I do want to include information from both descriptions for Rachel. How can I edit my search so that only records from 21 days ago are included but still includes multiple description information for my identifier. Let me know if you need any more information!
| eval Date=strptime(date,"%m/%d/%Y")
| where Date > relative_time(now(),"-21d@d")
↧