Splunk Search

Automate lookup search

rlautman
Path Finder

I use Splunks automated report facility for several reports - but I know have a requirement for a report that goes through several steps, creating and utilising lookup lists and delivering two distinct reports. The report flows is as follows:

Step 1: create a list of orders with the following - Buyers ID, Sellers ID, Products order, Order Status, Linked Order Reference

Step 2: Run same query as Step 1 except a lookup list of Linked Order Refernces is created

Step 3: List of Linked Order References is placed into another query and all Sellers ID associated with the Linked Orders are placed into another lookup list

Step 4: The list of Sellers IDs is placed into another query and a list of all orders and relevant information for these related to these Sellers IDs is created

Is it possible to automate this process using Splunk?

Tags (3)
0 Karma

Kate_Lawrence-G
Contributor

I think you may be able to use a summary index for this instead of all these lookups?
You could have multiple searches feed the available data into a larger index and then customize your report to run off that data with the fields you need already set.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...