<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic use query as a lookup for value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/use-query-as-a-lookup-for-value/m-p/274443#M82781</link>
    <description>&lt;P&gt;within an index i have Records with a Name and Id and some with just the ID.  &lt;/P&gt;

&lt;P&gt;sourcetype=A Name="Foo"  Id=23&lt;BR /&gt;
sourcetype=A Name="Blah" Id=24&lt;BR /&gt;
sourcetype=B Id = 24 Message="Found"&lt;BR /&gt;
sourcetype=B Id =23 Message="Lost"&lt;BR /&gt;
sourcetype=B Id=24 Message="Lost"&lt;/P&gt;

&lt;P&gt;I am looking to query and get &lt;/P&gt;

&lt;P&gt;Name="Foo" Id=23 Message="Lost"&lt;BR /&gt;
Name="Blah" Id=24 Message="Found"&lt;BR /&gt;
Name="Blah" Id=24 Message="Lost"&lt;/P&gt;

&lt;P&gt;basically wanting to use source a as a lookup i have tried join the syntaxes but no luck&lt;/P&gt;</description>
    <pubDate>Fri, 27 May 2016 13:57:28 GMT</pubDate>
    <dc:creator>leonardr</dc:creator>
    <dc:date>2016-05-27T13:57:28Z</dc:date>
    <item>
      <title>use query as a lookup for value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/use-query-as-a-lookup-for-value/m-p/274443#M82781</link>
      <description>&lt;P&gt;within an index i have Records with a Name and Id and some with just the ID.  &lt;/P&gt;

&lt;P&gt;sourcetype=A Name="Foo"  Id=23&lt;BR /&gt;
sourcetype=A Name="Blah" Id=24&lt;BR /&gt;
sourcetype=B Id = 24 Message="Found"&lt;BR /&gt;
sourcetype=B Id =23 Message="Lost"&lt;BR /&gt;
sourcetype=B Id=24 Message="Lost"&lt;/P&gt;

&lt;P&gt;I am looking to query and get &lt;/P&gt;

&lt;P&gt;Name="Foo" Id=23 Message="Lost"&lt;BR /&gt;
Name="Blah" Id=24 Message="Found"&lt;BR /&gt;
Name="Blah" Id=24 Message="Lost"&lt;/P&gt;

&lt;P&gt;basically wanting to use source a as a lookup i have tried join the syntaxes but no luck&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 13:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/use-query-as-a-lookup-for-value/m-p/274443#M82781</guid>
      <dc:creator>leonardr</dc:creator>
      <dc:date>2016-05-27T13:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: use query as a lookup for value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/use-query-as-a-lookup-for-value/m-p/274444#M82782</link>
      <description>&lt;P&gt;Try like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=A OR sourcetype=B | stats values(Name) as Name values(Message) as Message by Id
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 May 2016 14:22:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/use-query-as-a-lookup-for-value/m-p/274444#M82782</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-05-27T14:22:04Z</dc:date>
    </item>
  </channel>
</rss>

