<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Loop through splunk search for multiple values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693661#M235986</link>
    <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251958"&gt;@P_vandereerden&lt;/a&gt;&amp;nbsp;says, SPL is totally different from procedural languages. &amp;nbsp;You need to think differently. &amp;nbsp;One point is: explicit iteration should be used sparsely. &amp;nbsp;There are also lots of other elements in the illustrated code that make it "unSPL" and some unnecessary.&lt;/P&gt;&lt;P&gt;For a problem like this, it is better to follow my four golden rules ("four commandments") of asking answerable questions.&lt;/P&gt;&lt;P&gt;To ask an answerable data analytics question, follow these golden rules; nay, call them the four commandments:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Illustrate data input (in raw text, anonymize as needed), whether they are raw events or output from a search that volunteers here do not have to look at.&lt;/LI&gt;&lt;LI&gt;Illustrate the desired output from illustrated data.&lt;/LI&gt;&lt;LI&gt;Explain the logic between illustrated data and desired output&amp;nbsp;&lt;EM&gt;without&lt;/EM&gt;&amp;nbsp;SPL.&lt;/LI&gt;&lt;LI&gt;If you also illustrate attempted SPL, illustrate actual output and compare with desired output, explain why they look different&amp;nbsp;&lt;U&gt;to you&lt;/U&gt;&amp;nbsp;if that is not painfully obvious.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In your case, you also want to illustrate how desired output change when the token takes different values. &amp;nbsp;One more tip: Use Splunk's auto format feature to format SPL if there are more than a couple pipes. &amp;nbsp;Like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="xxx" source = "yyyyzzz" AND $DropdownValue$ AND Input
| eventstats max(_time) as maxTimestamp by desc
|  head 1
| dedup _time
| eval lastTriggered = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")
| stats values(lastTriggered) as lastTriggeredTime
| appendcols
    [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Output
    | eventstats max(_time) as maxTimestamp by desc
    | head 1
    | dedup _time
    | eval lastProcessed = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")
    | stats values(lastProcessed) as lastProcessedTime]
| appendcols
    [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Error
    | eventstats max(_time) as maxTimestamp by desc
    | head 1
    | dedup_time
    | eval lastErrored = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")]
| eval "COMPONENT ID"="$DropdownValue$"
| eval "Last Triggered Time"=lastTriggeredTime
| eval "Last Processed Time"=lastProcessedTime
| eval "Last Errored Time"=lastErrored
| table "COMPONENT ID", "Last Triggered Time", "Last Processed Time","Last Errored Time"
| fillnull value="NOT IN LAST 12 HOURS" "COMPONENT ID","Last Triggered Time", "Last Processed Time","Last Errored Time"&lt;/LI-CODE&gt;&lt;P&gt;After this formating, you can easily see why some commands are wasteful.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jul 2024 05:30:57 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2024-07-18T05:30:57Z</dc:date>
    <item>
      <title>Loop through splunk search for multiple values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693517#M235954</link>
      <description>&lt;P&gt;I want to get the below search executed and display the results in a table for all comma separated values that gets passed from dropdown.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="xxx" source = "yyyyzzz" AND $DropdownValue$ AND Input| eventstats max(_time) as maxTimestamp by desc| head 1 | dedup _time | eval lastTriggered = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")| stats values(lastTriggered) as lastTriggeredTime| appendcols [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Output| eventstats max(_time) as maxTimestamp by desc| head 1 | dedup_time | eval lastProcessed = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")| stats values(lastProcessed) as lastProcessedTime] | appendcols [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Error| eventstats max(_time) as maxTimestamp by desc| head 1 | dedup_time | eval lastErrored = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")]|eval "COMPONENT ID"="$DropdownValue$"|eval "Last Triggered Time"=lastTriggeredTime |eval "Last Processed Time"=lastProcessedTime| eval "Last Errored Time"=lastErrored | table "COMPONENT ID", "Last Triggered Time", "Last Processed Time","Last Errored Time" | fillnull value="NOT IN LAST 12 HOURS" "COMPONENT ID","Last Triggered Time", "Last Processed Time","Last Errored Time"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example if $dropdownValue$ is having ABC,DEV, then the entire above mentioned search should get executed twice and 2 rows od data should be displayed in the table. Can someone guide how this can be achieved?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 21:59:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693517#M235954</guid>
      <dc:creator>anmohan0</dc:creator>
      <dc:date>2024-07-16T21:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Loop through splunk search for multiple values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693525#M235956</link>
      <description>&lt;P&gt;This part suggests that the dropdown selections are values in the COMPONENT ID field:&lt;BR /&gt;&lt;EM&gt;"COMPONENT ID"="$DropdownValue$"&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;If that's the case, you could filter based on&lt;BR /&gt;"COMPONENT ID" IN ($&lt;EM&gt;DropdownValue&lt;/EM&gt;$)&lt;BR /&gt;and join the subsearches on COMPONENT ID rather than appending columns.&lt;BR /&gt;&lt;BR /&gt;Joins are not particularly efficient, so instead of that suggestion, I would look at pulling all the data from that index back in a single search, and conditionally evaluating the stats.&lt;BR /&gt;&lt;BR /&gt;Paul&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 20:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693525#M235956</guid>
      <dc:creator>P_vandereerden</dc:creator>
      <dc:date>2024-07-16T20:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Loop through splunk search for multiple values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693661#M235986</link>
      <description>&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251958"&gt;@P_vandereerden&lt;/a&gt;&amp;nbsp;says, SPL is totally different from procedural languages. &amp;nbsp;You need to think differently. &amp;nbsp;One point is: explicit iteration should be used sparsely. &amp;nbsp;There are also lots of other elements in the illustrated code that make it "unSPL" and some unnecessary.&lt;/P&gt;&lt;P&gt;For a problem like this, it is better to follow my four golden rules ("four commandments") of asking answerable questions.&lt;/P&gt;&lt;P&gt;To ask an answerable data analytics question, follow these golden rules; nay, call them the four commandments:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Illustrate data input (in raw text, anonymize as needed), whether they are raw events or output from a search that volunteers here do not have to look at.&lt;/LI&gt;&lt;LI&gt;Illustrate the desired output from illustrated data.&lt;/LI&gt;&lt;LI&gt;Explain the logic between illustrated data and desired output&amp;nbsp;&lt;EM&gt;without&lt;/EM&gt;&amp;nbsp;SPL.&lt;/LI&gt;&lt;LI&gt;If you also illustrate attempted SPL, illustrate actual output and compare with desired output, explain why they look different&amp;nbsp;&lt;U&gt;to you&lt;/U&gt;&amp;nbsp;if that is not painfully obvious.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In your case, you also want to illustrate how desired output change when the token takes different values. &amp;nbsp;One more tip: Use Splunk's auto format feature to format SPL if there are more than a couple pipes. &amp;nbsp;Like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="xxx" source = "yyyyzzz" AND $DropdownValue$ AND Input
| eventstats max(_time) as maxTimestamp by desc
|  head 1
| dedup _time
| eval lastTriggered = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")
| stats values(lastTriggered) as lastTriggeredTime
| appendcols
    [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Output
    | eventstats max(_time) as maxTimestamp by desc
    | head 1
    | dedup _time
    | eval lastProcessed = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")
    | stats values(lastProcessed) as lastProcessedTime]
| appendcols
    [search index="xxx" source = "yyyyzzz" sourcetype = "mule:rtf:per:logs" AND $DropdownValue$ AND Error
    | eventstats max(_time) as maxTimestamp by desc
    | head 1
    | dedup_time
    | eval lastErrored = strftime(_time, "%d/%m/%Y %H:%M:%S %Z")]
| eval "COMPONENT ID"="$DropdownValue$"
| eval "Last Triggered Time"=lastTriggeredTime
| eval "Last Processed Time"=lastProcessedTime
| eval "Last Errored Time"=lastErrored
| table "COMPONENT ID", "Last Triggered Time", "Last Processed Time","Last Errored Time"
| fillnull value="NOT IN LAST 12 HOURS" "COMPONENT ID","Last Triggered Time", "Last Processed Time","Last Errored Time"&lt;/LI-CODE&gt;&lt;P&gt;After this formating, you can easily see why some commands are wasteful.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 05:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/693661#M235986</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-18T05:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Loop through splunk search for multiple values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/709193#M239687</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251958"&gt;@P_vandereerden&lt;/a&gt;&amp;nbsp;and it worked as the way I wanted.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 06:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Loop-through-splunk-search-for-multiple-values/m-p/709193#M239687</guid>
      <dc:creator>anmohan0</dc:creator>
      <dc:date>2025-01-20T06:00:39Z</dc:date>
    </item>
  </channel>
</rss>

