Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is there a way to have different timescale for lookups than the actual search?

$
0
0
Hi, I am looking for a solution for this problem. I have implemented Lookup tables based on time and they are working fine. The issue I am having is that if the lookup table entry falls outside the search timescale it returns with no results. I wanted to see if there a way to stretch the lookup timeline more than the actual search. I know everyone likes the actual search string, but in this case it will not help. eg. I have a lookup table with an entry made say 24 hours ago as shown below. Unit 111 Version 1.1 Time 1:31pm 5/5/2016 If I search using lookup for Versions in the last 4 hours, it will not show the above entry. However, If i stretch it to last 7 days, it shows up properly. So here is my question (i could not find any documentation around it). I need a search than runs on the last 24 hours continuously but it should incorporate lookup entries for the Unit Versions from the last known entry which could be 1 week or even 30 days in the past. Sorry for all text. I am really hoping this is possible. Please help. Thanks a lot, Abhi

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>