<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to pass static string via lookup to stats command? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617447#M214574</link>
    <description>&lt;P&gt;I'm attempting to utilize a lookup to pass static strings to create 'stats' commands. The result is sent to the search but it's treated as a large string instead of the various&amp;nbsp; values/statistical operations that are part of the search. I'm wondering if there's a way to get Splunk to interpret the command as intended.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2022 18:31:27 GMT</pubDate>
    <dc:creator>dfphere</dc:creator>
    <dc:date>2022-10-18T18:31:27Z</dc:date>
    <item>
      <title>How to pass static string via lookup to stats command?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617447#M214574</link>
      <description>&lt;P&gt;I'm attempting to utilize a lookup to pass static strings to create 'stats' commands. The result is sent to the search but it's treated as a large string instead of the various&amp;nbsp; values/statistical operations that are part of the search. I'm wondering if there's a way to get Splunk to interpret the command as intended.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 18:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617447#M214574</guid>
      <dc:creator>dfphere</dc:creator>
      <dc:date>2022-10-18T18:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Pass static string via lookup to stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617451#M214577</link>
      <description>&lt;P&gt;Unfortunately it can't (yet) be done - I created a Splunk idea a couple of years ago for this&lt;/P&gt;&lt;P&gt;&lt;A href="https://ideas.splunk.com/ideas/EID-I-398" target="_blank"&gt;https://ideas.splunk.com/ideas/EID-I-398&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but it's not been adopted - although marked as 'future prospect'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 22:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617451#M214577</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-17T22:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Pass static string via lookup to stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617455#M214580</link>
      <description>&lt;P&gt;Bummer, but I upvoted to help the cause. Any chance you found a work around?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 23:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617455#M214580</guid>
      <dc:creator>dfphere</dc:creator>
      <dc:date>2022-10-17T23:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Pass static string via lookup to stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617457#M214582</link>
      <description>&lt;P&gt;Sadly no workaround - the idea of using externally defined control strings to influence SPL just isn't practically possible other than in the way represented in the idea.&lt;/P&gt;&lt;P&gt;I guess the 'workaround' is to try to understand your use case to see why you are trying to do that anyway and whether you really need it.&lt;/P&gt;&lt;P&gt;You can do some generic stuff with macros, but even then, not really dynamically, as macros are expanded _before_ the search is executed, so cannot take account of field values in the pipeline&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 23:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-pass-static-string-via-lookup-to-stats-command/m-p/617457#M214582</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-17T23:11:23Z</dc:date>
    </item>
  </channel>
</rss>

