<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group table results by lookup table value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401111#M116161</link>
    <description>&lt;P&gt;@aohls, glad I could help! it's converted to an answer, you can upvote and accept &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  &lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2019 12:51:23 GMT</pubDate>
    <dc:creator>DavidHourani</dc:creator>
    <dc:date>2019-06-13T12:51:23Z</dc:date>
    <item>
      <title>Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401103#M116153</link>
      <description>&lt;P&gt;We have a few servers clustered together and have created a lookup table that combines them. &lt;BR /&gt;
What I would like to do is use the lookup table in my search results to group the results by the combined name.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;CombinedName    Host1 Host2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the above example, I want the results in my search from &lt;CODE&gt;Host1&lt;/CODE&gt; and &lt;CODE&gt;Host2&lt;/CODE&gt; to get combined and show up as &lt;CODE&gt;CombinedName&lt;/CODE&gt;. I was attempting the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| lookup client-info.csv hostname, combinedName OUTPUT hostname,combinedName
|fields + combinedName
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I am not getting results back but I should be. Is there something I missed or a better way to do this?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 16:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401103#M116153</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-05-31T16:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401104#M116154</link>
      <description>&lt;P&gt;hi @aohls, could you please share the entire search you are trying to run ? Also could you please specify what the combinedName field should contain ? Is it the list of hosts ?&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 16:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401104#M116154</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-31T16:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401105#M116155</link>
      <description>&lt;P&gt;@DavidHourani here is my search. combinedName is just a name we use to represent a cluster of hosts. It is defined in the client-name.csv lookup.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;sourcetype="userlogins" &lt;BR /&gt;
| lookup client-name.csv hostname, combinedName OUTPUT hostname,combinedName &lt;BR /&gt;
| fields + combinedName &lt;BR /&gt;
| stats avg(responsetime) as averageResponse, count(_raw) AS eventCount by combinedName , operation&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 16:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401105#M116155</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-05-31T16:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401106#M116156</link>
      <description>&lt;P&gt;so in client-name.csv you have both hostname and combinedName and in your data you only have hostname, right ? If that's the case do the following :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="userlogins" | lookup client-name.csv hostname OUTPUT combinedName | stats avg(responsetime) as averageResponse, count AS eventCount by combinedName , operation
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 31 May 2019 16:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401106#M116156</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-31T16:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401107#M116157</link>
      <description>&lt;P&gt;Do you get results from &lt;CODE&gt;sourcetype="userlogins" | lookup client-name.csv hostname, combinedName OUTPUT hostname,combinedName | table hostname combinedName responseTime operation&lt;/CODE&gt;?  If not, the problem may be with your lookup file.  Verify all four fields have values.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 17:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401107#M116157</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-05-31T17:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401108#M116158</link>
      <description>&lt;P&gt;@DavidHourani It seems like your solution will work. @richgalloway identified the other issue; the lookup table is lower case but we have the hosts all capitalized. I believe this is causing a mismatch and not getting results back.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 17:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401108#M116158</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-05-31T17:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401109#M116159</link>
      <description>&lt;P&gt;Cool! let me know so I convert it to answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 17:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401109#M116159</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-31T17:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401110#M116160</link>
      <description>&lt;P&gt;@DavidHourani  This worked great once I resolved the case match issue. You can convert it to answered.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 12:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401110#M116160</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-06-13T12:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Group table results by lookup table value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401111#M116161</link>
      <description>&lt;P&gt;@aohls, glad I could help! it's converted to an answer, you can upvote and accept &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  &lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 12:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-table-results-by-lookup-table-value/m-p/401111#M116161</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-13T12:51:23Z</dc:date>
    </item>
  </channel>
</rss>

