<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add row to chart from lookup file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611915#M212742</link>
    <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_index" 
| search 
    [ inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as app_name] 
| table app_name stage_name stage_status 
| eval stage_name = "Stage - " + stage_name
| rename app_name as App 
| chart values(stage_status) by App, stage_name useother=f limit=0
| append
    [| inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as App]
| stats values(*) as * by App
| fillnull value="Not Executed"&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 05 Sep 2022 10:07:00 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-09-05T10:07:00Z</dc:date>
    <item>
      <title>How to add row to chart from lookup file?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611907#M212739</link>
      <description>&lt;P&gt;Hi Splunk community,&lt;/P&gt;
&lt;P&gt;I want to chart the data retrieved from index, filter the app_name field to match with ones in the lookup file. There will be some app_name values in lookup file not in the index, and they need to be added as new rows and labeled "Not executed" for their status.&lt;/P&gt;
&lt;P&gt;My SPL looks like below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="my_index" 
| search 
    [ inputlookup my_lookup 
    | table "App Name" 
    | rename "App Name" as app_name] 
| table app_name stage_name stage_status 
| eval stage_name = "Stage - " + stage_name
| rename app_name as App 
| chart values(stage_status) by App, stage_name useother=f limit=0&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here what I got:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;App&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage A&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage B&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage C&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage D&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;App_A&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;FAILED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I want it to look like this:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;App&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage A&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage B&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage C&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Stage D&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;App_A&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;FAILED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;PASSED&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;App_B&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="20%" height="25px"&gt;...&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;TD width="20%" height="25px"&gt;Not executed&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help and advise,&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 21:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611907#M212739</guid>
      <dc:creator>boxmetal</dc:creator>
      <dc:date>2022-09-05T21:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Add row to chart from lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611915#M212742</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_index" 
| search 
    [ inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as app_name] 
| table app_name stage_name stage_status 
| eval stage_name = "Stage - " + stage_name
| rename app_name as App 
| chart values(stage_status) by App, stage_name useother=f limit=0
| append
    [| inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as App]
| stats values(*) as * by App
| fillnull value="Not Executed"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 05 Sep 2022 10:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611915#M212742</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-05T10:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Add row to chart from lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611936#M212758</link>
      <description>&lt;P&gt;I tried to add the append command under the subsearch, but it does not chart as expected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The "Not Executed" values is added to stage_name field, and all previous field become null.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;App&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Stage - Not Executed&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;NULL&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="47px"&gt;&lt;SPAN&gt;App_A&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px"&gt;Not Executed&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="47px"&gt;&lt;DIV class=""&gt;FAILED&lt;/DIV&gt;&lt;DIV class=""&gt;PASSED&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&lt;SPAN&gt;App_B&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Not Executed&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Not Executed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;...&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Not Executed&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;Not Executed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 05 Sep 2022 11:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611936#M212758</guid>
      <dc:creator>boxmetal</dc:creator>
      <dc:date>2022-09-05T11:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Add row to chart from lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611940#M212761</link>
      <description>&lt;P&gt;What was the search you used for this result?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 11:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/611940#M212761</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-05T11:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Add row to chart from lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/612011#M212797</link>
      <description>&lt;P&gt;I added it append command under the subsearch like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_index" 
| search 
    [ inputlookup my_lookup 
    | table "App Name" 
    | rename "App Name" as app_name] 
| append
    [| inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as app_name]
| stats values(*) as * by app_name
| fillnull value="Not Executed"
| table app_name stage_name stage_status 
| eval stage_name = "Stage - " + stage_name
| rename app_name as App 
| chart values(stage_status) by App, stage_name useother=f limit=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And for your provided search, the chart result I got only has app_name field. So I changed it like above but seem no luck so far&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 02:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/612011#M212797</guid>
      <dc:creator>boxmetal</dc:creator>
      <dc:date>2022-09-06T02:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Add row to chart from lookup file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/612060#M212816</link>
      <description>&lt;LI-CODE lang="markup"&gt;index="my_index" 
| search 
    [ inputlookup my_lookup 
    | table "App Name" 
    | rename "App Name" as app_name] 
| table app_name stage_name stage_status 
| eval stage_name = "Stage - " + stage_name
| rename app_name as App 
| chart values(stage_status) by App, stage_name useother=f usenull=f limit=0
| append
    [| inputlookup my_lookup 
    | fields "App Name" 
    | rename "App Name" as App]
| stats values(*) as * by App
| fillnull value="Not Executed"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 06 Sep 2022 09:32:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-row-to-chart-from-lookup-file/m-p/612060#M212816</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-06T09:32:04Z</dc:date>
    </item>
  </channel>
</rss>

