<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Count of all query present in lookup file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Count-of-all-query-present-in-lookup-file/m-p/557563#M158346</link>
    <description>&lt;P&gt;I've created a lookup file with 2 columns like this, basically a lookup file containing list of search queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Value&lt;/P&gt;&lt;P&gt;Query1&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*xyz*&amp;nbsp; field1="fasdasdasdadasdasd"&lt;/P&gt;&lt;P&gt;Query2&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*abc*&amp;nbsp; field2 = "qweqweqweqweqwe"&lt;/P&gt;&lt;P&gt;Query3&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*pqr*&amp;nbsp; field3 = "zxzxczxczczx"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to get the count of each query using &lt;STRONG&gt;inputlookup and map command&lt;/STRONG&gt;, in such a way that it gives 0 result to and not omit the any query if count is 0, like this -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Count&lt;/P&gt;&lt;P&gt;Query1&amp;nbsp; &amp;nbsp; &amp;nbsp;| 200&lt;/P&gt;&lt;P&gt;Query2&amp;nbsp; &amp;nbsp; &amp;nbsp;| 0&lt;/P&gt;&lt;P&gt;Query3&amp;nbsp; &amp;nbsp; &amp;nbsp;|4500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone help please ?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 08:38:10 GMT</pubDate>
    <dc:creator>pjtbasu</dc:creator>
    <dc:date>2021-06-29T08:38:10Z</dc:date>
    <item>
      <title>Count of all query present in lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Count-of-all-query-present-in-lookup-file/m-p/557563#M158346</link>
      <description>&lt;P&gt;I've created a lookup file with 2 columns like this, basically a lookup file containing list of search queries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Value&lt;/P&gt;&lt;P&gt;Query1&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*xyz*&amp;nbsp; field1="fasdasdasdadasdasd"&lt;/P&gt;&lt;P&gt;Query2&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*abc*&amp;nbsp; field2 = "qweqweqweqweqwe"&lt;/P&gt;&lt;P&gt;Query3&amp;nbsp; &amp;nbsp; &amp;nbsp;| index=*pqr*&amp;nbsp; field3 = "zxzxczxczczx"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to get the count of each query using &lt;STRONG&gt;inputlookup and map command&lt;/STRONG&gt;, in such a way that it gives 0 result to and not omit the any query if count is 0, like this -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Count&lt;/P&gt;&lt;P&gt;Query1&amp;nbsp; &amp;nbsp; &amp;nbsp;| 200&lt;/P&gt;&lt;P&gt;Query2&amp;nbsp; &amp;nbsp; &amp;nbsp;| 0&lt;/P&gt;&lt;P&gt;Query3&amp;nbsp; &amp;nbsp; &amp;nbsp;|4500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone help please ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 08:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Count-of-all-query-present-in-lookup-file/m-p/557563#M158346</guid>
      <dc:creator>pjtbasu</dc:creator>
      <dc:date>2021-06-29T08:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Count of all query present in lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Count-of-all-query-present-in-lookup-file/m-p/557586#M158355</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/71017"&gt;@pjtbasu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you pass value from main search to map command it will enclosed it with double quote( as it is consider as value) and pass it.&lt;/P&gt;&lt;P&gt;So if your search is like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal eventtype=splunkd-access&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;map will consider like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search "index=_internal eventtype=splunkd-access"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this situation you will get 0 count always.&lt;/P&gt;&lt;P&gt;So I'm suggesting one trick to achieve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create &lt;SPAN&gt;&lt;STRONG&gt;Execute_Search&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;in savedsearches.conf.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Execute_Search]
search = $q$ | stats count as Count | eval Name="$name$" | table Name Count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and use this savedsearch with map command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|inputlookup YOUR_LOOKUP
| table Name,Value
| map search="| savedsearch Execute_Search q=$Value$ name=$Name$"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="Name,Value
Query1,index=_internal eventtype=splunkd-access
Query2,index=_internal eventtype=splunkd-log
Query3,index=_internal sourcetype=splunkd
" | multikv forceheader=1
| table Name,Value
| map search="| savedsearch Execute_Search q=$Value$ name=$Name$"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 11:17:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Count-of-all-query-present-in-lookup-file/m-p/557586#M158355</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-29T11:17:47Z</dc:date>
    </item>
  </channel>
</rss>

