Getting Data In

How to map my query with inputlookup values?

karthi2809
Builder

I am running script to get ping status of the servers and i onboarded the logs and extract filed as Servers.Now in my inputlookup i have 5 fields (ServerName,ApplicationName,Environment,Alias,IPAdress).So i need to map the query result with inputlookup.

Index=* sourcetype=StatusPing |rex field=_raw "^[^\|\n]*\|\s+(?P<Servers>[^ ]+)" | eval Status=case(Lost=0, "UP", Lost=2, "Warning", Lost=4, "Down")|append [|inputlookup PingStatus.csv|rename Servers as ServerName ]|table Alias,EnvironmentName,ApplicationName,ServerName,IPAddress,Lost,Status

Thanks in Advance

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Use lookup rather than inputlookup.

index=foo sourcetype=StatusPing 
| rex field=_raw "^[^\|\n]*\|\s+(?P<Servers>[^ ]+)" 
| eval Status=case(Lost=0, "UP", Lost=2, "Warning", Lost=4, "Down")
| rename Servers as ServerName
| lookup PingStatus.csv ServerName
| table Alias,EnvironmentName,ApplicationName,ServerName,IPAddress,Lost,Status

Don't use index=* in a production query.  Your Splunk admin will hate you for it.  🙂

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Use lookup rather than inputlookup.

index=foo sourcetype=StatusPing 
| rex field=_raw "^[^\|\n]*\|\s+(?P<Servers>[^ ]+)" 
| eval Status=case(Lost=0, "UP", Lost=2, "Warning", Lost=4, "Down")
| rename Servers as ServerName
| lookup PingStatus.csv ServerName
| table Alias,EnvironmentName,ApplicationName,ServerName,IPAddress,Lost,Status

Don't use index=* in a production query.  Your Splunk admin will hate you for it.  🙂

 

---
If this reply helps you, Karma would be appreciated.

karthi2809
Builder

Thanks

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...