<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to display limited results from a field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571718#M199219</link>
    <description>&lt;P&gt;To filter your results, use the &lt;FONT face="courier new,courier"&gt;search&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;where&lt;/FONT&gt; command.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | search failcode IN ("g-ab", "c-cd", "d-dd")&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;... | where IN(failcode, "g-ab", "c-cd", "d-dd")&lt;/LI-CODE&gt;&lt;P&gt;For better performance put the &lt;FONT face="courier new,courier"&gt;IN&lt;/FONT&gt; option from the &lt;FONT face="courier new,courier"&gt;search&lt;/FONT&gt; command above in the base search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo failcode IN ("g-ab", "c-cd", "d-dd")
| ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 20:04:59 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-10-20T20:04:59Z</dc:date>
    <item>
      <title>How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571716#M199218</link>
      <description>&lt;P&gt;I have a field named&lt;STRONG&gt; failcode&lt;/STRONG&gt;&amp;nbsp;with numerous fail code names structured like this:&lt;/P&gt;&lt;TABLE border="1" width="99.8442367601246%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;date&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;failcode&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;123&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;258&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;369&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;456&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;124&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;325&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;854&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;962&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;362&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-01&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-dd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;851&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;963&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;101&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;171&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;320&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;214&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;985&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;165&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;130&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;892&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-02&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-dd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;964&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;653&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;285&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;g-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;634&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;689&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;752&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;c-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;452&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-ab&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;365&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-bc&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;125&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-cd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;691&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="42.05607476635514%"&gt;2021-10-03&lt;/TD&gt;&lt;TD width="30.062305295950154%"&gt;d-dd&lt;/TD&gt;&lt;TD width="27.725856697819314%"&gt;354&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to only keep certain codes: &lt;STRONG&gt;g-ab&lt;/STRONG&gt;, &lt;STRONG&gt;c-cd&lt;/STRONG&gt;, and &lt;STRONG&gt;d-dd&lt;/STRONG&gt; and not display the rest in my results. Essentially I just want to display certain results from my &lt;STRONG&gt;failcode&lt;/STRONG&gt; column.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 19:32:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571716#M199218</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-10-20T19:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571718#M199219</link>
      <description>&lt;P&gt;To filter your results, use the &lt;FONT face="courier new,courier"&gt;search&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;where&lt;/FONT&gt; command.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | search failcode IN ("g-ab", "c-cd", "d-dd")&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;... | where IN(failcode, "g-ab", "c-cd", "d-dd")&lt;/LI-CODE&gt;&lt;P&gt;For better performance put the &lt;FONT face="courier new,courier"&gt;IN&lt;/FONT&gt; option from the &lt;FONT face="courier new,courier"&gt;search&lt;/FONT&gt; command above in the base search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo failcode IN ("g-ab", "c-cd", "d-dd")
| ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 20:04:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571718#M199219</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-20T20:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571727#M199223</link>
      <description>&lt;P&gt;Would this method also work with a search that is using a lookup table? I tried using the below but didn't come up with any results. Would this not work with a lookup table?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup myfile.csv
| where IN(failcode, "g-ab", "c-cd", "d-dd")
| ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 21:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571727#M199223</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-10-20T21:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571736#M199230</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230987" target="_blank" rel="noopener"&gt;@MikeB&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;inputlookup can be used to fetch results.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;| inputlookup myfile.csv 
| where failcode IN ("g-ab", "c-cd", "d-dd")&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Oct 2021 23:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571736#M199230</guid>
      <dc:creator>nmohammed</dc:creator>
      <dc:date>2021-10-20T23:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571847#M199273</link>
      <description>&lt;P&gt;Hmmm, I still cannot get any results to display. Is there something specific I should use after that such as using "fields" instead of "table" to display my results?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 16:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571847#M199273</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-10-21T16:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571867#M199275</link>
      <description>&lt;P&gt;are you able to see the contents of the lookup file created ? run the following command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup myfile.csv&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 17:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571867#M199275</guid>
      <dc:creator>nmohammed</dc:creator>
      <dc:date>2021-10-21T17:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571870#M199276</link>
      <description>&lt;P&gt;Yes, I'm able to see the entire contents of my lookup file. The file is structured as follows:&lt;BR /&gt;&lt;BR /&gt;_time, failcode, source, failcount&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 17:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571870#M199276</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2021-10-21T17:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to display limited results from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571896#M199286</link>
      <description>&lt;P&gt;It should work, I tried it out with csv file you shared.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It can either be permissions (but you're able to see contents of lookup using inputlookup).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the fieldnames (case-sensitive) &amp;amp; also spell-check&lt;/P&gt;&lt;P&gt;Try another way (replace with your filename) -&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup answers-571716.csv
| where failcode="g-ab" OR failcode="c-cd" OR failcode="d-dd"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 19:37:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-limited-results-from-a-field/m-p/571896#M199286</guid>
      <dc:creator>nmohammed</dc:creator>
      <dc:date>2021-10-21T19:37:14Z</dc:date>
    </item>
  </channel>
</rss>

