<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to display search with multiple lookup? [SOLVED] in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604454#M210246</link>
    <description>&lt;P&gt;Hello&lt;BR /&gt;I have several lookups and I would like to display the details on a date range but I can't really do it&lt;BR /&gt;I have tried several combinations but either I display the last one or I display too many elements&lt;BR /&gt;As a bonus if I could have the total it would be cool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup file1.csv
| append
    [| inputlookup file2.csv]
| append
    [| inputlookup file3.csv]
| append
    [| inputlookup file4.csv]
| append
    [| inputlookup file5.csv]
| append
    [| inputlookup file6.csv]
| sort - _time
| eval date = strftime(_time,"%Y-%m-%d")
| search date&amp;gt;2022-07-01 AND date&amp;lt;2022-07-04
| transpose 6
| sort - column
| search column=date OR column=count
| fields - column
| rename "row 1" as "name1", "row 2" as "name2", "row 3" as "name3", "row 4" as "name4", "row 5" as "name5", "row 6" as "name6"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2022 08:42:27 GMT</pubDate>
    <dc:creator>brad_</dc:creator>
    <dc:date>2022-07-12T08:42:27Z</dc:date>
    <item>
      <title>How to display search with multiple lookup? [SOLVED]</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604454#M210246</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I have several lookups and I would like to display the details on a date range but I can't really do it&lt;BR /&gt;I have tried several combinations but either I display the last one or I display too many elements&lt;BR /&gt;As a bonus if I could have the total it would be cool&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup file1.csv
| append
    [| inputlookup file2.csv]
| append
    [| inputlookup file3.csv]
| append
    [| inputlookup file4.csv]
| append
    [| inputlookup file5.csv]
| append
    [| inputlookup file6.csv]
| sort - _time
| eval date = strftime(_time,"%Y-%m-%d")
| search date&amp;gt;2022-07-01 AND date&amp;lt;2022-07-04
| transpose 6
| sort - column
| search column=date OR column=count
| fields - column
| rename "row 1" as "name1", "row 2" as "name2", "row 3" as "name3", "row 4" as "name4", "row 5" as "name5", "row 6" as "name6"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 08:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604454#M210246</guid>
      <dc:creator>brad_</dc:creator>
      <dc:date>2022-07-12T08:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to display search with multilple lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604459#M210250</link>
      <description>&lt;P&gt;It is not clear what you are trying to achieve - can you share some of the events (contents of csv files) and what your expected output would be&lt;/P&gt;&lt;P&gt;Having said that, you might want to use where command rather than search and use unformatted epoch times&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where _time &amp;gt; strptime("2022-07-01","%Y-%m-%d") AND _time &amp;lt; strptime("2022-07-04","%Y-%m-%d")
| transpose 6
| sort - column
| where column="_time" OR column="count"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 05 Jul 2022 14:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604459#M210250</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-05T14:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to display search with multilple lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604471#M210254</link>
      <description>&lt;P&gt;Hello sorry to be unclear&lt;BR /&gt;all lookup have the same model see below&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lookup.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20404i660B95C6B9AB35EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="lookup.PNG" alt="lookup.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;I need to display the items per line for each date of the range see the result file&lt;/P&gt;&lt;TABLE width="560"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="80"&gt;Date&lt;/TD&gt;&lt;TD width="80"&gt;file1&lt;/TD&gt;&lt;TD width="80"&gt;file2&lt;/TD&gt;&lt;TD width="80"&gt;file3&lt;/TD&gt;&lt;TD width="80"&gt;file4&lt;/TD&gt;&lt;TD width="80"&gt;file5&lt;/TD&gt;&lt;TD width="80"&gt;file&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;04/07/2022&lt;/TD&gt;&lt;TD&gt;235&lt;/TD&gt;&lt;TD&gt;235&lt;/TD&gt;&lt;TD&gt;366&lt;/TD&gt;&lt;TD&gt;4554&lt;/TD&gt;&lt;TD&gt;56&lt;/TD&gt;&lt;TD&gt;83&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;05/07/2022&lt;/TD&gt;&lt;TD&gt;210&lt;/TD&gt;&lt;TD&gt;300&lt;/TD&gt;&lt;TD&gt;125&lt;/TD&gt;&lt;TD&gt;12011&lt;/TD&gt;&lt;TD&gt;15&lt;/TD&gt;&lt;TD&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;06/07/2022&lt;/TD&gt;&lt;TD&gt;185&lt;/TD&gt;&lt;TD&gt;365&lt;/TD&gt;&lt;TD&gt;116&lt;/TD&gt;&lt;TD&gt;19468&lt;/TD&gt;&lt;TD&gt;26&lt;/TD&gt;&lt;TD&gt;57&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;07/07/2022&lt;/TD&gt;&lt;TD&gt;160&lt;/TD&gt;&lt;TD&gt;430&lt;/TD&gt;&lt;TD&gt;357&lt;/TD&gt;&lt;TD&gt;26925&lt;/TD&gt;&lt;TD&gt;67&lt;/TD&gt;&lt;TD&gt;127&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;08/07/2022&lt;/TD&gt;&lt;TD&gt;135&lt;/TD&gt;&lt;TD&gt;495&lt;/TD&gt;&lt;TD&gt;598&lt;/TD&gt;&lt;TD&gt;34382&lt;/TD&gt;&lt;TD&gt;108&lt;/TD&gt;&lt;TD&gt;198&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Total&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;925&lt;/TD&gt;&lt;TD&gt;1825&lt;/TD&gt;&lt;TD&gt;1562&lt;/TD&gt;&lt;TD&gt;97340&lt;/TD&gt;&lt;TD&gt;272&lt;/TD&gt;&lt;TD&gt;478&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I hope that it is clearer&lt;BR /&gt;Thx&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604471#M210254</guid>
      <dc:creator>brad_</dc:creator>
      <dc:date>2022-07-05T16:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to display search with multilple lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604477#M210258</link>
      <description>&lt;LI-CODE lang="markup"&gt;| inputlookup file1.csv
| rename count as file1
| append
    [| inputlookup file2.csv
    | rename count as file2]
| append
    [| inputlookup file3.csv
    | rename count as file3]
| append
    [| inputlookup file4.csv
    | rename count as file4]
| append
    [| inputlookup file5.csv
    | rename count as file5]
| append
    [| inputlookup file6.csv
    | rename count as file6]
| stats values(*) as * by _time
| addtotals col=t row=f label=Total labelfield=_time&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/604477#M210258</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-05T16:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to display search with multiple lookup? [SOLVED]</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/605267#M210472</link>
      <description>&lt;P&gt;Thx for your help&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 08:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-search-with-multiple-lookup-SOLVED/m-p/605267#M210472</guid>
      <dc:creator>brad_</dc:creator>
      <dc:date>2022-07-12T08:55:13Z</dc:date>
    </item>
  </channel>
</rss>

