<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combining Several lookups. in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528384#M35857</link>
    <description>&lt;P&gt;I'm sorry issue with the actual lookup&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Nov 2020 00:31:10 GMT</pubDate>
    <dc:creator>Mary666</dc:creator>
    <dc:date>2020-11-07T00:31:10Z</dc:date>
    <item>
      <title>Combining Several lookups.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528367#M35853</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Splunk newbie, I have been able to combine several lookups using | inputlookup, and also using | inputlookup append=t. However, I am not able to combine the lookup to the ones I have just created. I see I no longer get the must specify one or more lookup files error, but all of my values from my lookup are coming back null. Is my format correct for the code below:&lt;/P&gt;&lt;P&gt;| lookup X_Server_Status.csv&amp;nbsp; Server_Name OUTPUT Status&lt;/P&gt;&lt;P&gt;I want to display the current status of the server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 20:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528367#M35853</guid>
      <dc:creator>Mary666</dc:creator>
      <dc:date>2020-11-06T20:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Combining Several lookups.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528369#M35854</link>
      <description>&lt;P&gt;Please share the full query, if you can (sanitize as necessary).&amp;nbsp; You mention using both inputlookup and lookup, but it's not clear how they're being use in relation to each other.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 20:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528369#M35854</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-06T20:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Combining Several lookups.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528383#M35856</link>
      <description>&lt;P&gt;I figured out my error. It was an issue with the a&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2020 00:30:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528383#M35856</guid>
      <dc:creator>Mary666</dc:creator>
      <dc:date>2020-11-07T00:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Combining Several lookups.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528384#M35857</link>
      <description>&lt;P&gt;I'm sorry issue with the actual lookup&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2020 00:31:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Combining-Several-lookups/m-p/528384#M35857</guid>
      <dc:creator>Mary666</dc:creator>
      <dc:date>2020-11-07T00:31:10Z</dc:date>
    </item>
  </channel>
</rss>

