<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Import a text data with a index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168553#M48070</link>
    <description>&lt;P&gt;Your clarification was excellent; try this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search $database$ $datatable$ sourcetype="my_data" | stats values(vix_input_1_splitter_hive_tablename) BY vix_input_1_splitter_hive_dbname | rename vix_input_1_splitter_hive_dbname AS "Database Name" | rename vix_input_1_splitter_hive_tablename AS "Datatable Name"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 14 Aug 2015 14:31:17 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-08-14T14:31:17Z</dc:date>
    <item>
      <title>Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168549#M48066</link>
      <description>&lt;P&gt;Hello everyone, I'm starting with the development in splunk...&lt;/P&gt;

&lt;P&gt;Each time a new database or datatable and created on the server, I have a service that generates a text file with the respective Info thereof, for example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[hive_APOLLO_APOLLO_DATA]
vix.description = (hive orc) edb exit nbn database
vix.input.1.path = /data/tdc/prd/corp/base/edb/APOLLO/...
vix.provider = bud_hive_orc
vix.input.1.splitter.hive.dbname = APOLLO
vix.input.1.splitter.hive.tablename = APOLLO_DATA
vix.input.1.splitter.hive.fileformat = orc

[hive_APOLLO_EPI_IV_CLI]
vix.description = (hive orc) edb exit nbn database
vix.input.1.path = /data/tdc/prd/corp/base/edb/APOLLO/...
vix.provider = bud_hive_orc
vix.input.1.splitter.hive.dbname = APOLLO
vix.input.1.splitter.hive.tablename = EPI_IV_CLI
vix.input.1.splitter.hive.fileformat = orc

[hive_APOLLO_EPI_IV_NBN_CLI]
vix.description = (hive orc) edb exit nbn database
vix.input.1.path = /data/tdc/prd/corp/base/edb/APOLLO/...
vix.provider = bud_hive_orc
vix.input.1.splitter.hive.dbname = APOLLO
vix.input.1.splitter.hive.tablename = EPI_IV_NBN_CLI
vix.input.1.splitter.hive.fileformat = orc

...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Once the data is imported into splunk the need to show the dashboard the entire information for the file.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/52201-img-3.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;In this case when I click one of the results the system does the search and returns the information from block concerning the same, however, the index generated and generally for the file (main):&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/52202-img-4.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;What do I need and the index is generated based on information contained in square brackets ([hive_APOLLO_TEST_PARTITION]) so when I run the search system bring something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Main View
   DB1
      DB1.TBL1 (virtual.index.1) -&amp;gt; links to Child View (virtual.index.1)

 Child View (virtual.index.1)
 &amp;lt;Search results for splunk search: index=virtual.index.1&amp;gt;

 DB1=APOLLO
 TBL1=APOLLO_DATA
 virtual.index.1=hive_APOLLO_APOLLO_DATA
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sorry for the long text, someone help me?&lt;/P&gt;

&lt;P&gt;Thank you all!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168549#M48066</guid>
      <dc:creator>gsfiorese_au</dc:creator>
      <dc:date>2020-09-29T06:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168550#M48067</link>
      <description>&lt;P&gt;I am having a great deal of trouble understanding very much of your request and it would help if you added more detail to your question (you can re-edit it).  I &lt;EM&gt;think&lt;/EM&gt; that I understand this statement:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Once the data is imported into splunk the need to show the dashboard the entire information for the file.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To do this, you can use a search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | reverse | stats list(_raw) by source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will reconstitute every file almost exactly the way the file was when it was indexed.  Hopefully I am understanding that part of your question and it helps you.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2015 18:06:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168550#M48067</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-13T18:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168551#M48068</link>
      <description>&lt;P&gt;Hi Woodcock, &lt;/P&gt;

&lt;P&gt;Thanks for the reply and I'm sorry if I was not clear, if it is not uncomfortable try to explain better now.&lt;/P&gt;

&lt;P&gt;Every day the txt file (myfile.txt) is imported into splunk and the data are shown through the dashboard below:&lt;/P&gt;

&lt;P&gt;As I have many informations (1 for n) the visualization is compromised and too long, and many pages are generated and this complicates the search.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Apollo &amp;gt;&amp;gt; Table_BlaBla_1&lt;BR /&gt;
Apollo &amp;gt;&amp;gt; Table_BlaBla_2&lt;BR /&gt;
Apollo &amp;gt;&amp;gt; Table_BlaBla_3&lt;/P&gt;

&lt;P&gt;Gendesk &amp;gt;&amp;gt; Table_Genx_1&lt;BR /&gt;
Gendesk &amp;gt;&amp;gt; Table_Genx_2&lt;BR /&gt;
Gendesk &amp;gt;&amp;gt; Table_Genx_3&lt;BR /&gt;
Gendesk &amp;gt;&amp;gt; Table_Genx_4&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I need the header once appears, and the dependencies come down (something like a tree view)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Apollo&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Table_BlaBla_1&lt;BR /&gt;
Table_BlaBla_2&lt;BR /&gt;
Table_BlaBla_3&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Gendesk&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Table_Genx_1&lt;BR /&gt;
Table_Genx_2&lt;BR /&gt;
Table_Genx_3&lt;BR /&gt;
Table_Genx_4&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Below is the code I used to create the dashboard, if his reach to help me or anyone else will be grateful.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168551#M48068</guid>
      <dc:creator>gsfiorese_au</dc:creator>
      <dc:date>2020-09-29T06:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168552#M48069</link>
      <description>&lt;P&gt;Sorry I forget my code for dashboard:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;Databases and Datatables - Search&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;List of Databases and Datatables from HIVE&amp;lt;/description&amp;gt;
  &amp;lt;fieldset autoRun="true" submitButton="true"&amp;gt;    
    &amp;lt;input type="text" token="database"&amp;gt;
      &amp;lt;label&amp;gt;Enter an Database Name&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;&amp;lt;/default&amp;gt;
      &amp;lt;prefix&amp;gt;vix_input_1_splitter_hive_dbname=&amp;lt;/prefix&amp;gt;
      &amp;lt;sufix&amp;gt;&amp;lt;/sufix&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="datatable"&amp;gt;
      &amp;lt;label&amp;gt;Enter an Database Name&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;&amp;lt;/default&amp;gt;
      &amp;lt;prefix&amp;gt;vix_input_1_splitter_hive_tablename=&amp;lt;/prefix&amp;gt;
      &amp;lt;sufix&amp;gt;&amp;lt;/sufix&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;table&amp;gt;
       &amp;lt;title&amp;gt;Databases and Datatables list found in the file:&amp;lt;/title&amp;gt;
       &amp;lt;search&amp;gt;
       &amp;lt;query&amp;gt;
         search $database$ $datatable$ sourcetype="my_data"
         | table vix_input_1_splitter_hive_dbname vix_input_1_splitter_hive_tablename 
         | rename vix_input_1_splitter_hive_dbname AS "Database Name" 
         | rename vix_input_1_splitter_hive_tablename AS "Datatable Name"           
       &amp;lt;/query&amp;gt;
       &amp;lt;/search&amp;gt;   
       &amp;lt;!--earliestTime&amp;gt;-60m@m&amp;lt;/earliestTime--&amp;gt;
       &amp;lt;latestTime&amp;gt;now&amp;lt;/latestTime&amp;gt;
       &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
       &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
     &amp;lt;/table&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Tks,&lt;/P&gt;

&lt;P&gt;Gabriel&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2015 05:12:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168552#M48069</guid>
      <dc:creator>gsfiorese_au</dc:creator>
      <dc:date>2015-08-14T05:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168553#M48070</link>
      <description>&lt;P&gt;Your clarification was excellent; try this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search $database$ $datatable$ sourcetype="my_data" | stats values(vix_input_1_splitter_hive_tablename) BY vix_input_1_splitter_hive_dbname | rename vix_input_1_splitter_hive_dbname AS "Database Name" | rename vix_input_1_splitter_hive_tablename AS "Datatable Name"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Aug 2015 14:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168553#M48070</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-14T14:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Import a text data with a index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168554#M48071</link>
      <description>&lt;P&gt;Thank you!! Woodcock!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 00:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Import-a-text-data-with-a-index/m-p/168554#M48071</guid>
      <dc:creator>gsfiorese_au</dc:creator>
      <dc:date>2015-08-17T00:59:35Z</dc:date>
    </item>
  </channel>
</rss>

