This may sound odd, but I wonder if there's a query that will just return your lookup table. Basically, I want to create a pulldown-driven form in Splunk, and I want to populate the pulldown with the contents of specific lookup table. I could just paste the values in, I suppose, but I don't want to maintain that list in two places. Alternatively, I could run a splunk query that would likely return all the results of that lookup table, but that seems like a lot of overhead. Any thoughts?
Thanks!
-S.
Absolutely. | inputlookup <lookup name>
will pull the full lookup table.
Hello,
Can we search all the lookup table available in splunk ?
I tried below command but that didn't work
| inputlookup *.csv
Absolutely. | inputlookup <lookup name>
will pull the full lookup table.
I wouldn't suggest timechart for this. Rather, add something like: | dedup
| timechart span=1m distinct_count(value)
Okay, follow up: what if you want a list of distinct values. My lookup has some values that show up more than once in the same column -- how do I filter it down to one time?
I had a feeling. You splunk people are AWESOME! Truly.