<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are we doing wrong in our Splunk API request for inputlookup? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/608698#M211655</link>
    <description>&lt;P&gt;Hi Everyone, we have another internal team that is trying to use the API to return some data we built for them. Unfortunately, they aren't able to get the payload but only the headers. Can someone suggest a solution or what we are doing wrong? the below is the response from the splunk API on their call.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Target:&amp;nbsp;https://SomeHost:Port/servicesNS/user/search/search/jobs/export&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Request body:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;search=search inputlookup somefile.csv | table Day User emp_id Data&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Response:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;results preview='0'&amp;gt;
&amp;lt;meta&amp;gt;
&amp;lt;fieldOrder&amp;gt;
&amp;lt;field&amp;gt;Day&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;User&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;emp_id&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;Data&amp;lt;/field&amp;gt;
&amp;lt;/fieldOrder&amp;gt;
&amp;lt;/meta&amp;gt;
&amp;lt;/results&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Aug 2022 14:33:28 GMT</pubDate>
    <dc:creator>jnichols914</dc:creator>
    <dc:date>2022-08-09T14:33:28Z</dc:date>
    <item>
      <title>What are we doing wrong in our Splunk API request for inputlookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/608698#M211655</link>
      <description>&lt;P&gt;Hi Everyone, we have another internal team that is trying to use the API to return some data we built for them. Unfortunately, they aren't able to get the payload but only the headers. Can someone suggest a solution or what we are doing wrong? the below is the response from the splunk API on their call.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Target:&amp;nbsp;https://SomeHost:Port/servicesNS/user/search/search/jobs/export&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Request body:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;search=search inputlookup somefile.csv | table Day User emp_id Data&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Response:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;lt;results preview='0'&amp;gt;
&amp;lt;meta&amp;gt;
&amp;lt;fieldOrder&amp;gt;
&amp;lt;field&amp;gt;Day&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;User&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;emp_id&amp;lt;/field&amp;gt;
&amp;lt;field&amp;gt;Data&amp;lt;/field&amp;gt;
&amp;lt;/fieldOrder&amp;gt;
&amp;lt;/meta&amp;gt;
&amp;lt;/results&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 14:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/608698#M211655</guid>
      <dc:creator>jnichols914</dc:creator>
      <dc:date>2022-08-09T14:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk API request for inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/608705#M211658</link>
      <description>&lt;P&gt;It's not entirely clear what you're trying to achieve.&lt;/P&gt;&lt;P&gt;The search&lt;/P&gt;&lt;PRE&gt;search=search inputlookup somefile.csv&lt;/PRE&gt;&lt;P&gt;will try to find events which contain literarily "inputtlookup" and "somefile.csv" strings in them (and of course field named search with value "search" but that's most probably a placeholder for some other part of a search).&lt;/P&gt;&lt;P&gt;So your initial search matches no results and the table command has no data to process so you only get column headers.&lt;/P&gt;&lt;P&gt;If you want the contents of a lookup, you need an inputlookup command on its own:&lt;/P&gt;&lt;PRE&gt;| inputlookup somefile.csv | table your set of fields&lt;/PRE&gt;&lt;P&gt;If you want the lookup to be applied to results of a search, just use lookup command&lt;/P&gt;&lt;PRE&gt;your search | lookup somefile.csv field | table [...]&lt;/PRE&gt;&lt;P&gt;If you want to append the results of the inputlookup command to the results of a search, just use inputlookup with append=true option&lt;/P&gt;&lt;PRE&gt;your search | inputlookup append=true somefile.csv | table [...]&lt;/PRE&gt;</description>
      <pubDate>Mon, 08 Aug 2022 14:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/608705#M211658</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-08-08T14:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: What are we doing wrong in our Splunk API request for inputlookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/609017#M211774</link>
      <description>&lt;P&gt;Thanks Rick. We will give this a shot and let you know the results. Appreciate you helping.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2022 13:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/609017#M211774</guid>
      <dc:creator>jnichols914</dc:creator>
      <dc:date>2022-08-10T13:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: What are we doing wrong in our Splunk API request for inputlookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/609025#M211775</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;, thanks for leading us down the path. We actually had to append to get the data. What worked was the code below. Thank you for getting us there.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search=search NOT * | inputlookup somefile.csv append=true | table Day User emp_id Data&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 10 Aug 2022 14:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-are-we-doing-wrong-in-our-Splunk-API-request-for/m-p/609025#M211775</guid>
      <dc:creator>jnichols914</dc:creator>
      <dc:date>2022-08-10T14:04:07Z</dc:date>
    </item>
  </channel>
</rss>

