Alerting

Hi Team, what is the search query to remove the first two rows from lookup table

aaa2324
Explorer

Tried inputlookup=abc | search NOT “row value” ,, but still getting the rows 

I want to remove the entire two rows (first and second ) ; please help

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aaa2324,

let me understand: do you want to have ad search results all the lookup rows but not the first two rows or to delete the first two rows of a lookup?

in first case, you could run something like this:

| inputlookup abc.csv start=2
| table *

in the second case, you have to add the outputlookup command at the end of the search, something like this:

| inputlookup abc.csv start=2
| table *
| outputlookup abc.csv

You can find more infos at https://docs.splunk.com/Documentation/Splunk/8.1.0/SearchReference/Inputlookup

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...