I have an asset list. the owner changed for several assets. Now I just want to change the owner name against specific category hosts.
MY inital query is :
| inputlookup asset_lookup.csv | search category="exch" | replace "abc" WITH "xyz" IN owner
I tried with append but does not producing the required.
| makeresults
| eval _raw="category,owner
exch,abc
exch,def
send,ghi"
| multikv forceheader=1
| eval owner=if(category=="exch" AND owner=="abc","xyz",owner)
The answer has been corrected.
After this, you can update with outputcsv.
hi
thanks for reverting back.
I want to update the same asset lookup with the outcome of the results.
for example. in the existing asset lookup the ower for network devices are man1.
but now ownership changed to owner2. so now how to update this information in asset lookup.
https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Inputlookup
Referring above link the example 6 solve my problem.
The answer has been fixed. please confirm.
yes
problem fixed.
thanks
Do you mean that you accepted the answer?