<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: file with list source for search OR file with list of search request in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104166#M26968</link>
    <description>&lt;P&gt;@ryastrebov - thats what you &lt;EM&gt;think&lt;/EM&gt; you need to do. Running 1440 consecutive searches is not feasible - So we need to look at alternative methods. &lt;/P&gt;

&lt;P&gt;sample data, example of the end result&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2013 14:08:10 GMT</pubDate>
    <dc:creator>jonuwz</dc:creator>
    <dc:date>2013-04-23T14:08:10Z</dc:date>
    <item>
      <title>file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104155#M26957</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;
I have a csv-file that contains list of source, for example:&lt;BR /&gt;
    source&lt;BR /&gt;
    MySource1&lt;BR /&gt;
    MySource2&lt;BR /&gt;
    MySource3&lt;BR /&gt;
    ...&lt;BR /&gt;
I have also a search request, it is the same for all sources.&lt;BR /&gt;
I need to create automatic consistent search for all source - First search in MySource1, Second search in MySource2,...&lt;BR /&gt;
Each subsequent search should start only when the previous search is over.&lt;BR /&gt;
I am new in programming, unfortunately.&lt;/P&gt;

&lt;P&gt;I can also create text file with list of searches, if this can help to find of solution of my problem.&lt;BR /&gt;
Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 07:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104155#M26957</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T07:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104156#M26958</link>
      <description>&lt;P&gt;perhaps the &lt;CODE&gt;map&lt;/CODE&gt; search command can be of help here. Haven't used it myself, but you should take a look.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Map"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Map&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104156#M26958</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-23T09:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104157#M26959</link>
      <description>&lt;P&gt;Thank you! I read this link, but I believe that this will not work in my case, since the MAP is to be used in the previous search, and I have no such - the search for independent. Just after each previous search lookup and update this lookup is used in the next search. Therefore, it is important to wait for the completion of the previous search before you start the next search.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104157#M26959</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T09:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104158#M26960</link>
      <description>&lt;P&gt;How many lookups are we talking about? If it's just a few you should consider using subsearches for this.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:43:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104158#M26960</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-04-23T09:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104159#M26961</link>
      <description>&lt;P&gt;I have 1440 searches&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104159#M26961</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T09:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104160#M26962</link>
      <description>&lt;P&gt;Sorry, I should have been more explicit. My idea was that you'd use &lt;CODE&gt;inputlookup&lt;/CODE&gt; or &lt;CODE&gt;inputcsv&lt;/CODE&gt;, or as Ayn suggests, use a subsearch to 'create' the search results.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104160#M26962</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-23T09:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104161#M26963</link>
      <description>&lt;P&gt;1440 o_O&lt;/P&gt;

&lt;P&gt;I don't have a solution to your problem, sorry. Could you tell us more about why you want to run 1440 searches sequentially? Maybe there is another way to achieve the same end goal?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 10:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104161#M26963</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-04-23T10:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104162#M26964</link>
      <description>&lt;P&gt;Customer make 1 source per minute. Final solution will work in real time. Now I want to  verify of my lookup per day. Source data contain unique attribute that for security purposes later in the log does not appear. This unique attribute is replaced by by some temporary attribute, and I am using lookup looking for all the events associated with this attribute, using a bunch of unique attribute - a temporary attribute. I can't use transaction, because this is very slowly method.  In one source contains approximately 400000 events.  And I have to treat them in a minute. So I use the lookup.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 10:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104162#M26964</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T10:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104163#M26965</link>
      <description>&lt;P&gt;I try using of inputcsv command, but I don't know how to use lines from csv as source. &lt;BR /&gt;
search source=sourcecsv is not working.&lt;BR /&gt;
My CSV contains lines as follows:&lt;/P&gt;

&lt;P&gt;sourcecsv&lt;BR /&gt;
/home/folder/MySource1.gz&lt;BR /&gt;
/home/folder/MySource2.gz&lt;/P&gt;

&lt;P&gt;Why my search request not working?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 12:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104163#M26965</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T12:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104164#M26966</link>
      <description>&lt;P&gt;You need to update your question with &lt;/P&gt;

&lt;P&gt;1) sample data&lt;BR /&gt;
2) an example of what the end result should look like.&lt;/P&gt;

&lt;P&gt;Its very hard to understand your requirements without this.&lt;/P&gt;

&lt;P&gt;its almost certain you can achieve what you want with stats / chart.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 13:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104164#M26966</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-04-23T13:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104165#M26967</link>
      <description>&lt;P&gt;I need to substitute in the search query values of source ​​from a text file. Once I conducted a search on a single value of source from file, I need to move on to the next value.&lt;BR /&gt;
If it is possible to quickly choose the order (by name) values ​​of source from sourtsetype, to me it is also nice.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 13:22:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104165#M26967</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T13:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104166#M26968</link>
      <description>&lt;P&gt;@ryastrebov - thats what you &lt;EM&gt;think&lt;/EM&gt; you need to do. Running 1440 consecutive searches is not feasible - So we need to look at alternative methods. &lt;/P&gt;

&lt;P&gt;sample data, example of the end result&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 14:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104166#M26968</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-04-23T14:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104167#M26969</link>
      <description>&lt;P&gt;==Update==&lt;/P&gt;

&lt;P&gt;So if you have a file like below (call it tmsi_lookup.csv):&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;tmsi,tmsi_old&lt;BR /&gt;
value1,value2&lt;BR /&gt;
value3,value4&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You can then do:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;source=mobile_source | lookup tmsi_lookup.csv tmsi_old OUTPUT tmsi&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This will take the "&lt;CODE&gt;tmsi_old&lt;/CODE&gt;" field of events in source "&lt;CODE&gt;mobile_source&lt;/CODE&gt;" and lookup the corresponding tmsi from the lookup file and populate it into the "tmsi" field.&lt;/P&gt;

&lt;P&gt;Does this help more?&lt;/P&gt;

&lt;P&gt;==Orig==&lt;/P&gt;

&lt;P&gt;Map Command will do this. However, as mentioned by jonuwz, a more efficient search can be done if the sources all contain similar information.&lt;/P&gt;

&lt;P&gt;Example (with similar information)&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;source=MySource1 OR source=MySource2 | stats sum(myField) by source&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Example (let's just mash a bunch of crap together)&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;|inputlookup MySources.csv | map [ source=$sourcecsv$ | stats count ]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The more information you provide, I can write better searches to get your end result.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 14:32:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104167#M26969</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-04-23T14:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104168#M26970</link>
      <description>&lt;P&gt;Thank you for your answer.&lt;BR /&gt;
I'll try to explain in more detail. Sorry, my English is poor.&lt;BR /&gt;
I analyze log of mobile operator. &lt;BR /&gt;
This log contains IMSI (unique identifier of SIM-card), TMSI (temporary ID), TMSI_OLD (previous TMSI), Base station, etc. IMSI is not present in the log at all times for safety. In this case, the IMSI in the log is replaced by a _. I create lookup to track the chain of TMSI-TMSI_OLD and to replace _ by IMSI. My lookup contain values IMSI, TMSI. In the case of a lookup multiple identical IMSI, the old value is removed.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104168#M26970</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2020-09-28T13:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104169#M26971</link>
      <description>&lt;P&gt;The amount of data per day is 1440 files - one file per minute. One file - one source. Each file contains about 400,000 events.&lt;BR /&gt;
Now I need to know if my lookup works correctly. To do this, I want to check the entire chain of the day, unloading at each intermediate search results csv-file. Upload a file I can do. The only thing that I have now does not work - make SPLUNK consistently to search all of 1440 source. I created a csv file containing a list of all the resources in the right order. &lt;BR /&gt;
Now I need to take entry of this file, to present it as a source and search for it. This I can't do it.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 15:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104169#M26971</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T15:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104170#M26972</link>
      <description>&lt;P&gt;But even though each is a source, they should have a common sourcetype. So in the search, just do "&lt;CODE&gt;sourcetype=mobile_sourcetype&lt;/CODE&gt;" or what ever the sourcetype is.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 15:08:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104170#M26972</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-04-23T15:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104171#M26973</link>
      <description>&lt;P&gt;Yes, it is. I have sourcetype that contain all sources. But how can it help?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 18:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104171#M26973</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T18:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: file with list source for search OR file with list of search request</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104172#M26974</link>
      <description>&lt;P&gt;alacercogitatus, yes, I use this approach. But the customer asked me to check my lookup is by testing it on daily data. And the question now is exactly how I read a line from the csv-file and use this line as name of source.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 18:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-with-list-source-for-search-OR-file-with-list-of-search/m-p/104172#M26974</guid>
      <dc:creator>ryastrebov</dc:creator>
      <dc:date>2013-04-23T18:47:55Z</dc:date>
    </item>
  </channel>
</rss>

