Reporting

how to use inputlookup in subsearch

mvaradarajam
Path Finder

Hi All,
i have search like this,

|savedsearch [search index=_internal |eval tnow6 = now() | convert ctime(tnow6) | eval s=substr(tnow6,15,15) |eval r=substr(s,0,2)|eval SwitcherValue2=case(r%2=1,"alert1",r%2=0,"alert2")|dedup SwitcherValue2|return $SwitcherValue2]|table _time * threshold|makecontinuous _time

here alert1 and alert2 are the saved searches,but i am facing problem sometimes splunk deamon not response.i thought due to index search taken long time so my search has timed out.

how to use inputlookup instead of index="_internal".

here my query every 1 minute my saved search has changed.

can u plz help me

0 Karma
1 Solution

somesoni2
Revered Legend

Try this:

 |savedsearch [| stats count | eval r=tonumber(strftime(now(),"%M"))|eval SwitcherValue2=case(r%2=1,"alert1",r%2=0,"alert2")|dedup SwitcherValue2|return $SwitcherValue2]|table _time * threshold|makecontinuous _time

View solution in original post

somesoni2
Revered Legend

Try this:

 |savedsearch [| stats count | eval r=tonumber(strftime(now(),"%M"))|eval SwitcherValue2=case(r%2=1,"alert1",r%2=0,"alert2")|dedup SwitcherValue2|return $SwitcherValue2]|table _time * threshold|makecontinuous _time

somesoni2
Revered Legend

Then it should be some other problem. Check the error logs in _internal index to what is the problem.

Reference post:http://answers.splunk.com/answers/50485/splunkd-daemon-is-not-responding-the-read-operation-timed-ou...

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...