<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup data not population in final part of query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/lookup-data-not-population-in-final-part-of-query/m-p/667752#M229076</link>
    <description>&lt;P&gt;The query field (like the search field) are special cases in subqueries as they are not passed to the outer search, only their values are. This is why the final query field is empty.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 23:11:04 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-11-07T23:11:04Z</dc:date>
    <item>
      <title>lookup data not population in final part of query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-data-not-population-in-final-part-of-query/m-p/667751#M229075</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;i have the below query where i have a lookup&amp;nbsp; file with Error messages im trying to match the error messages in the lookup and then matching those in the rawdata and showing in table. However my final result query field is coming as empty rest all are populating. Need help in the query i was trying to add before the table command | lookup&amp;nbsp;ErrorMessage.csv&amp;nbsp; query OUTPUT query but not working need help&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=abc host="LINUX123" " source="/new/dir/apps/servers/service*.log"&amp;nbsp; "Error data*"&amp;nbsp; [ | inputlookup ErrorMessage.csv | fields + ErrorMessage | rename ErrorMessage as query] | table _time,host,query, _raw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;lookup file content&lt;/P&gt;&lt;P&gt;ErrorMessage.csv&lt;/P&gt;&lt;P&gt;File Not Found&lt;/P&gt;&lt;P&gt;Error data in client transacton&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 22:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-data-not-population-in-final-part-of-query/m-p/667751#M229075</guid>
      <dc:creator>vk1544</dc:creator>
      <dc:date>2023-11-07T22:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: lookup data not population in final part of query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-data-not-population-in-final-part-of-query/m-p/667752#M229076</link>
      <description>&lt;P&gt;The query field (like the search field) are special cases in subqueries as they are not passed to the outer search, only their values are. This is why the final query field is empty.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 23:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-data-not-population-in-final-part-of-query/m-p/667752#M229076</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-07T23:11:04Z</dc:date>
    </item>
  </channel>
</rss>

