Hello,
I have below TSTATS command which is checking the specifig index population with events per day:
| tstats count WHERE (index=_internal AND sourcetype=splunkd) OR (index=B) by host,sourcetype,index,_time span=1d
I would like to modify it to run the search on only hosts which are in the lookup list servers.csv.
Can you please help me with modification?
I think I see the problem. An "AND" was missing before the subsearch. I've corrected my original answer.
Add the lookup in a subsearch with the where clause.
| tstats count WHERE (index=_internal AND sourcetype=splunkd) OR (index=B) AND [ | inputlookup servers.csv | return 1000 host] by host,sourcetype,index,_time span=1d
Thank you @richgalloway , for your assistance. I have checked the query and I have error:
"may have returned partial results. Try running your search again. If you see this error repeatedly, review search.log for details or contact your Splunk administrator."
Did you follow the instructions in the error message? What did you see in search.log?
I think here is the error:
"
08-06-2021 07:34:37.521 ERROR TsidxStats [60531 searchOrchestrator] - Incorrect WHERE clause : [ AND 1000 csv host inputlookup list return server splunk [ OR index::* [ AND index::_internal sourcetype::splunkd ] ] ]
"
08-06-2021 07:34:37.521 ERROR TsidxStats [60531 searchOrchestrator] - WHERE clause is not an exact query
I think I see the problem. An "AND" was missing before the subsearch. I've corrected my original answer.
If your problem is resolved, then please click the "Accept as Solution" button to help future readers.
Thank you very much, I think the problem is solved!