<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Merge dataset from tstat with data from external *.csv file. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426488#M122166</link>
    <description>&lt;P&gt;Simple way to do this would be something like this:&lt;/P&gt;

&lt;P&gt;| from datamodel:"dataset_name_here" | inputlookup append=t inputlook_name_here.csv&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:45:31 GMT</pubDate>
    <dc:creator>Azeemering</dc:creator>
    <dc:date>2020-09-29T19:45:31Z</dc:date>
    <item>
      <title>Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426485#M122163</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have to merge dataset with data from csv file. &lt;BR /&gt;
CSV file is well added.&lt;/P&gt;

&lt;P&gt;Dataset:&lt;BR /&gt;
ACTION,&lt;BR /&gt;
CLASS,&lt;BR /&gt;
CURRENT_PAGE,&lt;BR /&gt;
F_WorkFlowNumber,&lt;BR /&gt;
FULL_TIME&lt;/P&gt;

&lt;P&gt;map.csv:&lt;BR /&gt;
CURRENT_PAGE,&lt;BR /&gt;
KIND&lt;/P&gt;

&lt;P&gt;CURRENT_PAGE is common field.&lt;/P&gt;

&lt;P&gt;I have to show data from dataset filtered by KIND?&lt;/P&gt;

&lt;P&gt;How can I achieve this ?&lt;/P&gt;

&lt;P&gt;Best&lt;BR /&gt;
Dawid&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426485#M122163</guid>
      <dc:creator>Czakanski</dc:creator>
      <dc:date>2020-09-29T19:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426486#M122164</link>
      <description>&lt;P&gt;Is the CSV data added as lookup table file?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 15:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426486#M122164</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-01T15:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426487#M122165</link>
      <description>&lt;P&gt;Somesoni2: yes of course... is fully readable by splunk&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 17:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426487#M122165</guid>
      <dc:creator>Czakanski</dc:creator>
      <dc:date>2018-06-01T17:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426488#M122166</link>
      <description>&lt;P&gt;Simple way to do this would be something like this:&lt;/P&gt;

&lt;P&gt;| from datamodel:"dataset_name_here" | inputlookup append=t inputlook_name_here.csv&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426488#M122166</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2020-09-29T19:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426489#M122167</link>
      <description>&lt;P&gt;If you just want to add the &lt;CODE&gt;KIND&lt;/CODE&gt; field from the lookup for lines with matching &lt;CODE&gt;CURRENT_PAGE&lt;/CODE&gt; value, to the results of a dataset search, then that sounds like a typical job for the &lt;CODE&gt;lookup&lt;/CODE&gt; command: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Lookup"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So in your case (you might need to replace &lt;CODE&gt;map.csv&lt;/CODE&gt; with the name you defined for this lookup in Splunk):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...your search that returns the dataset results ...
| lookup map.csv CURRENT_PAGE OUTPUT KIND
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will add the KIND column to the search results, and you can add further search commands to filter / sort / count whatever you want &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 08:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426489#M122167</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-04T08:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426490#M122168</link>
      <description>&lt;P&gt;yes, I know but unfortunately this commmand doesn't associate records by common field.&lt;/P&gt;

&lt;P&gt;Output looks like:&lt;BR /&gt;
record from datamodel,&lt;BR /&gt;
record from csv,&lt;BR /&gt;
record from datamodel,&lt;BR /&gt;
record from csv,&lt;/P&gt;

&lt;P&gt;Instead of:&lt;BR /&gt;
ACTION, CLASS, F_WorkFlowNumber, FULL_TIME, CURRENT_PAGE, KIND&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426490#M122168</guid>
      <dc:creator>Czakanski</dc:creator>
      <dc:date>2020-09-29T19:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426491#M122169</link>
      <description>&lt;P&gt;That doesn't add the KIND field as a column to his dataset search results, that just glues the content of the lookup to the bottom of his search results. The way I understand his question a simple  &lt;CODE&gt;| lookup&lt;/CODE&gt; command would suffice.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 08:20:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426491#M122169</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-04T08:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426492#M122170</link>
      <description>&lt;P&gt;Yes it was that i lookin for but my main question was: how to do it with "tstats".&lt;/P&gt;

&lt;P&gt;Current query:&lt;/P&gt;

&lt;P&gt;| from datamodel:"DATAMODEL"&lt;BR /&gt;
| lookup map.csv CURRENT_PAGE &lt;BR /&gt;
| where FULL_TIME &amp;gt; 0 and FULL_TIME &amp;lt; 10000000 and FORM="specified form from dropdown menu"&lt;/P&gt;

&lt;P&gt;but how to transform it to "tstats"?&lt;/P&gt;

&lt;P&gt;best &lt;BR /&gt;
Dawid&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426492#M122170</guid>
      <dc:creator>Czakanski</dc:creator>
      <dc:date>2020-09-29T19:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426493#M122171</link>
      <description>&lt;P&gt;Don't think that comment was aimed at my answer, was it? @richgalloway may have linked it wrongly?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 13:51:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426493#M122171</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-04T13:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426494#M122172</link>
      <description>&lt;P&gt;Guess this comment belongs to my answer?&lt;/P&gt;

&lt;P&gt;To use a tstats datamodel search, you just need to change that first line. I'm not much of an expert on tstats datamodel search syntax, so if you need specific help with writing the tstats query, that would have to come from someone else.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 13:54:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426494#M122172</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-06-04T13:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Merge dataset from tstat with data from external *.csv file.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426495#M122173</link>
      <description>&lt;P&gt;so I will repeat that question:&lt;/P&gt;

&lt;P&gt;Yes it was that i lookin for but my main question was: how to do it with "tstats".&lt;/P&gt;

&lt;P&gt;Current query:&lt;/P&gt;

&lt;P&gt;| from datamodel:"DATAMODEL"&lt;BR /&gt;
| lookup map.csv CURRENT_PAGE &lt;BR /&gt;
| where FULL_TIME &amp;gt; 0 and FULL_TIME &amp;lt; 10000000 and FORM="specified form from dropdown menu"&lt;/P&gt;

&lt;P&gt;but how to transform it to "tstats"?&lt;/P&gt;

&lt;P&gt;I am lookin for solution like:&lt;BR /&gt;
| tstats avg(FULL_TIME) from datamodel="DATAMODEL"&lt;BR /&gt;
| lookup map.csv CURRENT_PAGE &lt;BR /&gt;
| where FULL_TIME &amp;gt; 0 and FULL_TIME &amp;lt; 10000000 and FORM="specified form from dropdown menu"&lt;/P&gt;

&lt;P&gt;but without pipe before lookup (I know it's necessary)&lt;/P&gt;

&lt;P&gt;best &lt;BR /&gt;
Dawid&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Merge-dataset-from-tstat-with-data-from-external-csv-file/m-p/426495#M122173</guid>
      <dc:creator>Czakanski</dc:creator>
      <dc:date>2020-09-29T19:51:16Z</dc:date>
    </item>
  </channel>
</rss>

