Splunk Enterprise

help on a subsearch from inputlookup

jip31
Motivator

hello

In host.csv, I have 4 fields : HOSTNAME, SITE, DEPARTMENT, CATEGORY

 

[| inputlookup host_OnOff.csv 
| fields HOSTNAME SITE DEPARTMENT CATEGORY | rename HOSTNAME as host
] `OnOff` 
| stats latest(_time) as _time by host SITE CATEGORY DEPARTMENT

 

 As you can see, I need to cross these fields with the host there is in `OnOff` in order to stats the value after

But i have no values displayed

what is wrong please?

Tags (1)
0 Karma

jip31
Motivator

Is anybody can help please?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...