Getting Data In

Is there a way to automatically perform a lookup followed by an eval to create a calculated field?

Engager

Hi,

I'm somewhat new to setting up the free Splunk, but have been playing with it and am super impressed so far. Unfortunately, I ran into an issue that I'm having trouble resolving, and was hoping for some assistance.

I noticed that the Props.conf documentation mentions that:

Splunk processes calculated fields
after field extraction and field
aliasing but before lookups

This is further re-inforced by the "Define calculated fields" documentation which says:

You cannot base calculated fields on
lookup fields. It won't work if you
try.

Unfortunately, I really want to do this. Specifically, I'd like to use the values that I am retrieving from the automated lookup in an evaluated field whenever querying results from a specific host.

If this cannot be done through Props.conf, I was wondering if there is another way to automatically perform a lookup followed by an eval on a specific field for a specific host?

It works brilliantly, when I manually do so in the search box, but I'd like to make the field appear automatically.

Any help would be greatly appreciated. Thanks!

0 Karma

Esteemed Legend

You understand correctly; you can do this, but only at search time. The dox are telling you that you cannot put everything into .conf files and have it all be automatic. That may be a bummer but it just means that the last parts of your stuff needs to be done at search time and saved off in the text of each saved search.

What you CAN do is use an eventtype which contain the search-time search strings and then you start your search like this:

eventtype=MyEventType

You can also use a macro which is also evaluated at search-time and far less cumbersome and allows you to have a single place to update your stuff when you need to, instead of updating every saved search.

0 Karma

Builder

Can you please provide the search query (which you executed mannually) along with the search which needs lookup changes?

0 Karma

SplunkTrust
SplunkTrust

Splunk search time order of operations handles eval prior to lookup. You cannot really change that unfortunately. You might could make an external lookup command script that does the calculation and the lookup and returns the result you want for the new field.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!