<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is Placeholder? How to create it? How it works in lookup? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590890#M205706</link>
    <description>&lt;P&gt;In general, a placeholder is something that - as the name suggests - holds the place. It is usually used instead of a real data, for example, to make sure that the data structure is right.&lt;/P&gt;&lt;P&gt;Most probably someone who created the lookup put a "PLACEHOLDER" value there to make clear that this is not an example of a real production data but it's just put there to keep the table structure with something inside.&lt;/P&gt;&lt;P&gt;It's in no way a special value for the lookup. It's treated as any other lookup value.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Mar 2022 16:04:41 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-03-25T16:04:41Z</dc:date>
    <item>
      <title>What is Placeholder? How to create it and how does it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590879#M205701</link>
      <description>&lt;P&gt;Can someone help with Splunk Placeholder?&lt;/P&gt;
&lt;P&gt;What is Placeholder? How to create it? How does it work in lookup?&lt;/P&gt;
&lt;P&gt;How to make changes to existing Placeholder&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexspunkshell_0-1648221388516.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18776i4AC424D05206E444/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexspunkshell_0-1648221388516.png" alt="alexspunkshell_0-1648221388516.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 21:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590879#M205701</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2022-03-28T21:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590880#M205702</link>
      <description>&lt;P&gt;Please tell us more.&amp;nbsp; Where did &lt;FONT face="courier new,courier"&gt;Wlist.csv&lt;/FONT&gt; come from?&amp;nbsp; What app is it?&amp;nbsp; "PLACEHOLDER" must have been inserted by the author of the lookup file or the app.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 15:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590880#M205702</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-03-25T15:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590890#M205706</link>
      <description>&lt;P&gt;In general, a placeholder is something that - as the name suggests - holds the place. It is usually used instead of a real data, for example, to make sure that the data structure is right.&lt;/P&gt;&lt;P&gt;Most probably someone who created the lookup put a "PLACEHOLDER" value there to make clear that this is not an example of a real production data but it's just put there to keep the table structure with something inside.&lt;/P&gt;&lt;P&gt;It's in no way a special value for the lookup. It's treated as any other lookup value.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 16:04:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590890#M205706</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-25T16:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590899#M205707</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; Thanks for your response&lt;/P&gt;&lt;P&gt;I have a below query. It uses the lookup and I can get the results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, when I check that lookup table there is no data. It just shows a placeholder.&lt;/P&gt;&lt;P&gt;I also checked in lookup table &amp;amp; lookup definition. But I am unable to find such a lookup name available but I am getting the results for my query.&lt;/P&gt;&lt;P&gt;Could you please help me with how it is working here?&lt;/P&gt;&lt;P&gt;index=* component=HostWide NOT [|inputlookup wlist.csv | fields host]&lt;BR /&gt;| eval used_cpu = 100 - 'data.cpu_idle_pct'&lt;BR /&gt;| stats avg(used_cpu) as used_cpu by host&lt;BR /&gt;| fieldformat used_cpu=round(used_cpu,1)&lt;BR /&gt;| where used_cpu &amp;gt; `200_cpu_threshold`&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexspunkshell_0-1648225965100.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18781i763CAAFFEEE855E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexspunkshell_0-1648225965100.png" alt="alexspunkshell_0-1648225965100.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 16:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590899#M205707</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2022-03-25T16:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590907#M205713</link>
      <description>&lt;P&gt;This is a relatively normal practice - you either define a lookup or a macro to store some configuration parameters. In your case it's supposed to be a list of hosts which should for whatever reason be excluded from your search.&lt;/P&gt;&lt;P&gt;This way you externalize the configuration part from the logic.&lt;/P&gt;&lt;P&gt;Let's say you create an app which provides some reports and dashboards. If you "export" the settings to an alias or lookup, you can easily maintain the dashboards/reports/whatevers regardless of what the user of the app configured in those aliases or lookups. This way you can easily maintain your app and upgrade functionality and searches behind the app functionality and it doesn't touch user's configuration.&lt;/P&gt;&lt;P&gt;For example - if I create an app with a dashboard pulling data from an index containing events regarding, let's say, your OpenStack infrastructure. As I have no knowledge about your splunk environment I have no way of knowing where you store your events. So I can either hardcode index names into my searches making the app very inconvenient for you to use since you have to conform strictly to index names (which could be conflicting with some other apps if they were written equally badly) or I can externalize that index definition into an alias or lookup. This way I'll put into my app search like&lt;/P&gt;&lt;PRE&gt;`openstack_indexes` &amp;lt;my_search&amp;gt;&lt;/PRE&gt;&lt;P&gt;or&lt;/P&gt;&lt;PRE&gt;[ | inputlookup openstack_indexes | table index ] &amp;lt;my_search&amp;gt;&lt;/PRE&gt;&lt;P&gt;And you wanting to use my app have to define a macro called openstack_indexes which will expand to something like&lt;/P&gt;&lt;PRE&gt;index=my_openstack_events&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;or a lookup which has field called index holding index names.&lt;/P&gt;&lt;P&gt;And coming back to your case - if your wlist.csv lookup contains only the placeholder you effectively don't add any reasonable constraints on your search so it works as if that condition using inputlookup was not present at all (because you're adding a condition of NOT host=PLACEHOLDER to your search.&lt;/P&gt;&lt;P&gt;If you added some lines to the wlist.csv lookup, with values of host1, host2 and host3 in the host field (the notes field is ignored in your subsearch) the first part of your search would effectively get expanded after the subsearch execution to&lt;/P&gt;&lt;PRE&gt;index=* component=HostWide NOT (host=host1 OR host=host2 OR host=host3 OR host=PLACEHOLDER)&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Assuming that you left the PLACEHOLDER where it is.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 17:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590907#M205713</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-25T17:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590957#M205736</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; Thanks for your detailed information.&lt;/P&gt;&lt;P&gt;Now I want to edit the info in the existing lookup file. Can u please help me with how to download the original lookup? Where I can find it?&lt;/P&gt;&lt;P&gt;I can find in Setting --&amp;gt; Lookup&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the lookup is showing a placeholder, how to make the changes in the placeholder?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Mar 2022 07:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590957#M205736</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2022-03-26T07:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: What is Placeholder? How to create it? How it works in lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590960#M205738</link>
      <description>&lt;P&gt;There are several ways of modifying lookups:&lt;/P&gt;&lt;P&gt;1) Use outputlookup command to write results of your search to a lookup&lt;/P&gt;&lt;P&gt;2) Delete old csv file and upload new one (works with csv-backed lookups)&lt;/P&gt;&lt;P&gt;3) Install lookup editor app - &lt;A href="https://splunkbase.splunk.com/app/1724/" target="_blank"&gt;https://splunkbase.splunk.com/app/1724/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Mar 2022 08:15:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-Placeholder-How-to-create-it-and-how-does-it-works-in/m-p/590960#M205738</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-26T08:15:10Z</dc:date>
    </item>
  </channel>
</rss>

