Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I exclude a group of the mac address found at specific time?

$
0
0
I have a dataset with a lot of mac address captured. I would like to excluded all mac address that arrived between 0h until 6h. But these mac can still appear after 6h. For example: DATE TIME MAC 01/01/2015 01:00:00 00:00:00:00:00:01 01/01/2015 03:00:00 00:00:00:00:00:01 01/01/2015 09:00:00 00:00:00:00:00:01 01/01/2015 10:00:00 00:00:00:00:00:02 As you can see above, just 00:00:00:00:02 mac wil should remain in dataset, because the other arrive between 0 until 6h. How can I do the search?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>