Splunk Enterprise

How to append /write only new results to outputlookup file

Ashwini008
Builder

Hi 

I want to write my results into outputlookup from saved search. but only when new results are there it should append it to mu lookup.which i am failing to do so

query| outputlookup append=true output.csv. This is writing multiple copies of same data into lookup.

quyery|[|inputlookup output.csv |dedup S] |outputlookup output.csv append=true. This isnt working

Any suggestions

Labels (2)
0 Karma

Ashwini008
Builder

UPDATE :

This worked for me

query | outputlookup output.csv append=true| append[| inputlookup append=true output.csv]| dedup Source | outputlookup output.csv

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try append=false

0 Karma

manjunathmeti
Champion

If field S in output.csv is part of index and sourcetype then you can try below query:

index=index sourcetype=sourcetype NOT [|inputlookup output.csv | dedup S | fields S] | outputlookup output.csv append=true
0 Karma

Ashwini008
Builder

@ITWhisperer Tried,but still multiple values.

@manjunathmeti My output.csv is empty. So have to write my index data to output.csv.Query is failing at this point,it shows zero results

index=index sourcetype=sourcetype NOT [|inputlookup output.csv | dedup S | fields S] 

 

Tags (2)
0 Karma

dm2
Explorer

Hi, I have the same issue but its not working for me..

I first created the lookup and save the search as a report, and then i need to edit my query to append ONLY new values. The current query does not push values at all.

 
 

index="rapid7_threat_intelligence" type="Domain"

|table _time, source, type, value

|outputlookup DOMAIN_IOC_ACTIVE.csv append=true

| append [ | inputlookup append=true DOMAIN_IOC_ACTIVE.csv]

| dedup value

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...