Splunk Search

Automate lookup search

rlautman
Path Finder

I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes through several steps, creating and utilising lookup lists and delivering two distinct reports. The report flows is as follows:

Step 1: create a list of orders with the following - Buyers ID, Sellers ID, Products order, Order Status, Linked Order Reference

Step 2: Run same query as Step 1 except a lookup list of Linked Order Refernces is created

Step 3: List of Linked Order References is placed into another query and all Sellers ID associated with the Linked Orders are placed into another lookup list

Step 4: The list of Sellers IDs is placed into another query and a list of all orders and relevant information for these related to these Sellers IDs is created

Is it possible to automate this process using Splunk?

Tags (3)
0 Karma

Kate_Lawrence-G
Contributor

I think you may be able to use a summary index for this instead of all these lookups?
You could have multiple searches feed the available data into a larger index and then customize your report to run off that data with the fields you need already set.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...