<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Write to Output lookup in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/550326#M91394</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;. this helps&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 May 2021 05:28:53 GMT</pubDate>
    <dc:creator>vijaysubramania</dc:creator>
    <dc:date>2021-05-04T05:28:53Z</dc:date>
    <item>
      <title>Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547931#M91147</link>
      <description>&lt;P&gt;HI Team,&lt;/P&gt;&lt;P&gt;Need one help, I want to run a schedule for the below search events&amp;nbsp; every 1 hr and capture the inportant fields&amp;nbsp; like responseStatus, r&lt;SPAN class="t"&gt;equestMethod,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;requestURL, servicePath, Total request, hour, day,&amp;nbsp; etc. and&amp;nbsp;&lt;/SPAN&gt;write to outputfile in csv. So that I can use this report for my dashboards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea behind this is becase, our application logs millions of events per day and if we want to look for the historical data for reports, it takes long time to run and load the dashboard.&lt;/P&gt;&lt;P&gt;I want to run this every hour and append the data it in the existing csv file.&lt;/P&gt;&lt;P&gt;I tried the lookup but didn't work for me. Any solutions welcome&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;time=2021-04-14T17:57:07&lt;/SPAN&gt;+&lt;SPAN class="t"&gt;00:00&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requestId=751411798490203&lt;/SPAN&gt; &lt;SPAN class="t"&gt;traceId=751411798490203&lt;/SPAN&gt; &lt;SPAN class="t"&gt;servicePath=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;/ecp/&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;remoteAddr=71.74.45.8&lt;/SPAN&gt; &lt;SPAN class="t"&gt;clientIp=24.161.128.196&lt;/SPAN&gt; &lt;SPAN class="t"&gt;clientAppVersion=NOT_AVAILABLE&lt;/SPAN&gt; &lt;SPAN class="t"&gt;app_version=-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;apiKey=72c07648-ea14-34f2-abed-e38263580b5c&lt;/SPAN&gt; &lt;SPAN class="t"&gt;oauth_leg=2-legged&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authMethod=oauth&lt;/SPAN&gt; &lt;SPAN class="t"&gt;apiAuth=true&lt;/SPAN&gt; &lt;SPAN class="t"&gt;apiAuthPath=/ecp/&lt;/SPAN&gt; &lt;SPAN class="t"&gt;oauth_version=1.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;target_bg=default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requestHost=api.spectrum.net&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requestPort=8080&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requestMethod=GET&lt;/SPAN&gt; &lt;SPAN class="t"&gt;requestURL=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;/ecp/entitlements/v2/entitlements&lt;/SPAN&gt;?&lt;SPAN class="t"&gt;divisionId=NEW.004&lt;/SPAN&gt;&amp;amp;&lt;SPAN class="t"&gt;accountNumber=28290420&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;requestSize=560&lt;/SPAN&gt; &lt;SPAN class="t"&gt;responseStatus=200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;responseSize=8422&lt;/SPAN&gt; &lt;SPAN class="t"&gt;responseTime=0.025&lt;/SPAN&gt; &lt;SPAN class="t"&gt;userAgent=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;IPVS&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;mapTEnabled=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;F&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;charterClientIp=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;V-1&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;IP-24.161.128.196&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;SourcePort-&lt;/SPAN&gt;|&lt;SPAN class="t"&gt;TrafficOriginID-24.161.128.196&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;sourcePort=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;oauth_consumer_key=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;72c27648-ea14-44f2-abed-e38263580b5c&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;x_pi_auth_failure=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;pi_log=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;pi_ngxgw_access&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 18:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547931#M91147</guid>
      <dc:creator>vijaysubramania</dc:creator>
      <dc:date>2021-04-14T18:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547939#M91148</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/53447"&gt;@vijaysubramania&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;you can use the outputlookup comand&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"your search" | table "the list of your fields" | outputlookup "lookup name" &lt;/LI-CODE&gt;&lt;P&gt;you can check the documentation&lt;/P&gt;&lt;P&gt;here:&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Outputlookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;p.s if you want save your data in append you need to add the append condition in your search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"your search" | table "the list of your fields" | outputlookup "lookup name" append=true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 19:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547939#M91148</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-14T19:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547944#M91149</link>
      <description>&lt;P&gt;Thanks for the inputs.&lt;/P&gt;&lt;P&gt;But, I want to see the data count in horizontal format with count.&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="22px"&gt;200&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;201&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;202&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;203&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;204&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;Total&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;Application&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;Date&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;Day&lt;/TD&gt;&lt;TD width="5%" height="22px"&gt;Time&lt;/TD&gt;&lt;TD width="5%" height="22px"&gt;RequestURL&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="22px"&gt;1&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;2&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;4&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;5&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;8&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;20&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;ECP&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;04/14/21&lt;/TD&gt;&lt;TD width="10%" height="22px"&gt;Wed&lt;/TD&gt;&lt;TD width="5%" height="22px"&gt;14:00&lt;/TD&gt;&lt;TD width="5%" height="22px"&gt;Entitlements&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 19:37:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547944#M91149</guid>
      <dc:creator>vijaysubramania</dc:creator>
      <dc:date>2021-04-14T19:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547998#M91153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/53447"&gt;@vijaysubramania&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;in this case you need the transpose comand.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transpose&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Now I don't know your dataset but let me show you an example:&lt;/P&gt;&lt;P&gt;normal search have this results:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunk_web_access | stats count by status &lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_0-1618481605527.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13780iBD6B206AD774A12B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_0-1618481605527.png" alt="aasabatini_0-1618481605527.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;use transpose comand at the end of the search and specify the header_field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunk_web_access | stats count by status | transpose header_field=status&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aasabatini_1-1618481754062.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13781iFE95D853C4F11FD1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aasabatini_1-1618481754062.png" alt="aasabatini_1-1618481754062.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;if you want filter the first field column use table after the search&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunk_web_access | stats count by status | transpose header_field=status | table 200 303 304 404&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope can help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 10:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/547998#M91153</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-15T10:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/549704#M91300</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;I actually tried other way too using timechart and look up the statstics gives the data in the format i need. But, will this data can be saved in the outputlookup file. I want to use this outputlookup file to plot the charts for multiple services reporting&lt;BR /&gt;"my search" | dedup requestId | timechart span=1h count by responseStatus limit=0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaysubramania_0-1619650350782.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13961i42D5BF7CEB11BE9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vijaysubramania_0-1619650350782.png" alt="vijaysubramania_0-1619650350782.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your query&lt;BR /&gt;"my search" | dedup requestId | stats count by responseStatus limit=0 | transpose header_field=responseStatus&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaysubramania_1-1619650715118.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13962iBA21B66CF74C5248/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vijaysubramania_1-1619650715118.png" alt="vijaysubramania_1-1619650715118.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;outputlookup&lt;/P&gt;&lt;P&gt;"mysearch" |&amp;nbsp; | dedup requestId | stats count by responseStatus limit=0 | transpose header_field=responseStatus | outputlookup "ecpstats.csv" append=true&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaysubramania_2-1619651073432.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13963i7C8E3829F2FEE050/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vijaysubramania_2-1619651073432.png" alt="vijaysubramania_2-1619651073432.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 23:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/549704#M91300</guid>
      <dc:creator>vijaysubramania</dc:creator>
      <dc:date>2021-04-28T23:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Write to Output lookup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/550326#M91394</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;. this helps&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 05:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/550326#M91394</guid>
      <dc:creator>vijaysubramania</dc:creator>
      <dc:date>2021-05-04T05:28:53Z</dc:date>
    </item>
    <item>
      <title>use input lookup table to calculate success%</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/551043#M91491</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have created the lookupfile which i created with Status count of each status codes, Application Name and day. I want to calculate the success % from the data I saved without performing any transpose as I am capturing all the http status codes each day. The purpose is as the volume of data is too high, I am using lookup table to reduce the load and faster response&lt;/P&gt;&lt;P&gt;| inputlookup MC_V2_DAILY.csv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vijaysubramania_0-1620633450450.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14098iA2C04CBB94C8F193/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vijaysubramania_0-1620633450450.png" alt="vijaysubramania_0-1620633450450.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 07:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Write-to-Output-lookup/m-p/551043#M91491</guid>
      <dc:creator>vijaysubramania</dc:creator>
      <dc:date>2021-05-10T07:58:57Z</dc:date>
    </item>
  </channel>
</rss>

