Archive

Is there a way to determine if different Splunk rules are utilizing the same input lookup table without looking through each rule?

Ghanayem1974
Path Finder

Is there a way to determine if different Splunk rules are utilizing the same input lookup table without looking through each rule?

0 Karma
1 Solution

damien_chillet
Builder

You can retrieve SPL for each rules and extract lookup names with a regex using something like this:

| rest /servicesNS/-/-/saved/searches
| rex field=search max_match=10 "inputlookup\s+(append=true\s+)?(?P<lookup>[^\.\s\]]+)"
| mvexpand lookup
| fields title lookup
| stats values(title) by lookup

Tweak regex depending on your use case (this one extract lookups that appear after the inputlookup command).

View solution in original post

0 Karma

damien_chillet
Builder

You can retrieve SPL for each rules and extract lookup names with a regex using something like this:

| rest /servicesNS/-/-/saved/searches
| rex field=search max_match=10 "inputlookup\s+(append=true\s+)?(?P<lookup>[^\.\s\]]+)"
| mvexpand lookup
| fields title lookup
| stats values(title) by lookup

Tweak regex depending on your use case (this one extract lookups that appear after the inputlookup command).

View solution in original post

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!