Splunk Enterprise

How to add new entry to lookups and older values are overridden by new values?

sagar_shubham23
Explorer

Why i am getting Duplicate entries while using outputlookups.

Query: 

|inputlookup append=t test1_checks.csv| eval Alert_type="test2", Correlated_alert="test2", Correlation_type=0| outputlookup append=true test1_checks.csv

Result:

Alert Type      Correlated_alert

test2                   test2

test2                   test2

test2                    test2

 

I need only one entry for all kind of entries in Alert_type and Correlated_alert.

 

Kindly help

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Give this a try

|inputlookup append=t test1_checks.csv
| append [| makeresults | eval Alert_type="test2", Correlated_alert="test2", Correlation_type=0 | table Alert_type Correlated_alert Correlation_type ]
| stats last(Correlation_type) as Correlation_type by Alert_type Correlated_alert
| outputlookup append=true test1_checks.csv

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The append=true option to outputlookup tells Splunk to keep the existing lookup file content.  To replace the content with the current result set, use append=false (the default).

 

| inputlookup test1_checks.csv
| eval Alert_type="test2", Correlated_alert="test2", Correlation_type=0
| outputlookup test1_checks.csv

 

As @somesoni2 mentioned, to eliminate duplicate entries, you need to use the stats or dedup command.

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Give this a try

|inputlookup append=t test1_checks.csv
| append [| makeresults | eval Alert_type="test2", Correlated_alert="test2", Correlation_type=0 | table Alert_type Correlated_alert Correlation_type ]
| stats last(Correlation_type) as Correlation_type by Alert_type Correlated_alert
| outputlookup append=true test1_checks.csv
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...