Archive
Highlighted

How to push the search query to lookup file

Explorer

If I write a search query and want to push the search query code to my lookup. Ho to do it??

Tags (1)
0 Karma
Highlighted

Re: How to push the search query to lookup file

Champion

The community more details about your queries and lookup in order to be helpful.

Please provide a summary of what is stored in the lookup and what your queries look like.

0 Karma
Highlighted

Re: How to push the search query to lookup file

SplunkTrust
SplunkTrust

if the results are what youre looking for, just pipe to table and outputlookup. something like that:
my base search | table field1 field2 fieldn | ouputlookup mysearch.csv

0 Karma
Highlighted

Re: How to push the search query to lookup file

SplunkTrust
SplunkTrust

is it the code you want to push, or the output?

0 Karma
Highlighted

Re: How to push the search query to lookup file

Explorer

Yes, I want to push the splunk query code in lookup.

For Example : - index="internal" and I want to push index="internal" into the lookup.

0 Karma
Highlighted

Re: How to push the search query to lookup file

SplunkTrust
SplunkTrust

just throwing out there but if you want to capture the searches, you can go with something like this:
| history | table _time search | outputlookup searches.csv

0 Karma
Highlighted

Re: How to push the search query to lookup file

Engager

The query itself won't give you this ability.

However, all queries are stored in the _audit index. So you could search this index for the desired queries and then output the result into a lookup file.

index=_audit action=search
0 Karma