<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputlookup not working in federated serach in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619976#M106861</link>
    <description>&lt;P&gt;Perhaps you could modify the query to use &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; instead of &lt;FONT face="courier new,courier"&gt;inputlookup&lt;/FONT&gt;?&lt;/P&gt;&lt;P&gt;Another, less optimal, option is to put the maintenance list in an index instead of a lookup file.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 19:29:09 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-11-07T19:29:09Z</dc:date>
    <item>
      <title>Why is inputlookup not working in federated search?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619943#M106853</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;i have a established query which is working fine. But when i try to add the inputlookup to the query, its not working. i am using a federated search.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My need is to configure a maintenance table as a csv lookup&amp;nbsp; and refer to it in the query.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i try to access the csv file via inputlookup, i get error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please suggest is there a way to configure maintenance for a particular backend via lookup table and refer to it in the query. i want to exclude the backend host for a particular date and time.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Query below:&lt;/P&gt;
&lt;P&gt;index="federated:XXX"&amp;nbsp; ("HTTP response code" OR "url-open" OR "Host connection failed")&amp;nbsp; NOT "HTTP response code 2**" | rex field=_raw "https://(?&amp;lt;backend&amp;gt;.*)\:" | rex field=_raw "gtid\(\w{1,24}\): (?&amp;lt;error&amp;gt;.*)"|&lt;BR /&gt;rex field=_raw "^&amp;lt;\d+&amp;gt;(?P&amp;lt;date&amp;gt;\d+\-\d+\-\d+\w+:\d+:\d+\.\d+)[^ \n]* (?P&amp;lt;host&amp;gt;\w+)\s+\[(?P&amp;lt;domain&amp;gt;[^\]]+)" | eval thresholdValue = case(backend=="******" AND domain=="*****", 500, backend=="abcd.com" AND domain!="abcd-ALERTS", 350, backend=="ertyu.com" AND domain=="ertyu", 1000, backend!="qwerty.com", 100) | stats count by domain,backend,error,source,thresholdValue | sort -count | where count&amp;gt;thresholdValue | eval Priority=if(count&amp;gt;200,"3","4") | eval createINCTicket="0" | table domain,backend,error,source,thresholdValue,Priority,count,createINCTicket | lookup incsearch DOMAIN AS domain URL AS backend OUTPUT APPCODE AS BackendAppcode CREATETICKET AS CT INCIDENT AS incident&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maintenance csv lookup&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="721"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="205"&gt;maint_backend&lt;/TD&gt;
&lt;TD width="117"&gt;maint_domain&lt;/TD&gt;
&lt;TD width="99"&gt;date_hour_start&lt;/TD&gt;
&lt;TD width="93"&gt;date_hour_end&lt;/TD&gt;
&lt;TD width="106"&gt;date_mday_start&lt;/TD&gt;
&lt;TD width="101"&gt;date_mday_end&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;abcd.com&lt;/TD&gt;
&lt;TD&gt;abcd-abcd&lt;/TD&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;3&lt;/TD&gt;
&lt;TD&gt;6&lt;/TD&gt;
&lt;TD&gt;7&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 08 Nov 2022 16:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619943#M106853</guid>
      <dc:creator>sangeeta</dc:creator>
      <dc:date>2022-11-08T16:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619948#M106854</link>
      <description>&lt;P&gt;What error do you get?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 17:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619948#M106854</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-07T17:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619953#M106855</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This federated search is not currently supported.&amp;nbsp;The search job has failed due to an error&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 17:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619953#M106855</guid>
      <dc:creator>sangeeta</dc:creator>
      <dc:date>2022-11-07T17:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619955#M106856</link>
      <description>&lt;P&gt;There you go.&amp;nbsp; You're trying to do something that is not supported.&lt;/P&gt;&lt;P&gt;Federated Search requires lookup tables to be maintain on both the Federated and Remote search heads.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 18:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619955#M106856</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-07T18:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619970#M106858</link>
      <description>&lt;P&gt;Yes. I have configured the same lookup table on both places.&amp;nbsp; Still i get error&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 19:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619970#M106858</guid>
      <dc:creator>sangeeta</dc:creator>
      <dc:date>2022-11-07T19:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619971#M106859</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;inputlookup&lt;/FONT&gt; command is not allowed in Federated Search.&amp;nbsp; See&lt;STRONG&gt;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Search/Searchacrosslocalandremotedeployments#Restrictions_for_standard_mode_federated_search" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Search/Searchacrosslocalandremotedeployments#Restrictions_for_standard_mode_federated_search&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 19:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619971#M106859</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-07T19:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619973#M106860</link>
      <description>&lt;P&gt;Thank you.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; . i dont want to keep editing the query everytime a particular host goes into maintenance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way to configure maintenance..&lt;/P&gt;&lt;P&gt;Appreciate your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 19:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619973#M106860</guid>
      <dc:creator>sangeeta</dc:creator>
      <dc:date>2022-11-07T19:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup not working in federated serach</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619976#M106861</link>
      <description>&lt;P&gt;Perhaps you could modify the query to use &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; instead of &lt;FONT face="courier new,courier"&gt;inputlookup&lt;/FONT&gt;?&lt;/P&gt;&lt;P&gt;Another, less optimal, option is to put the maintenance list in an index instead of a lookup file.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 19:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-inputlookup-not-working-in-federated-search/m-p/619976#M106861</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-07T19:29:09Z</dc:date>
    </item>
  </channel>
</rss>

