Splunk Search

Display Input Lookup Data

New Member

Hi Team,

How to display lookup fields along with search fields.

search Query
index=AA* host=ABC source=/tmp/processMonitor* instance=XYZ apphome =*** | lookup boxdata host | search boxlivestate="LIVE" | stats latest(state) as Status by host, apphome, instance, appmon | table host apphome instance appmon boxlivestate

Iam not getting anything under boxlivestate, Is thr any way to display ??

boxdata
boxenv boxlivestate boxlocation boxmodel boxos boxpatch boxrack boxrfb boxver host
QA NOTLIVE ABC-DE HPXYZQ RHAS 1234 324 lxmcp 6.9 hostny01

Expecting output
host apphome instance appmon Status boxlivestate
ABC /xy/abc abc 1 down Live

Thanks
Harsha

0 Karma

SplunkTrust
SplunkTrust

@harsush, please reverse the lookup pipe which should be after stats command. In your current query the stats command is removing enriched field/s from lookup including boxlivestate.

index=AA* host=ABC source=/tmp/processMonitor* instance=XYZ apphome =*** 
| stats latest(state) as Status by host, apphome, instance, appmon 
| lookup boxdata host 
| search box_live_state="LIVE"
| table host apphome instance appmon box_live_state

Also as per performance consideration, lookup should be performed after transforming commands ensuring records are reduced prior to correlating with the lookup file: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup#Optimizing_your_lookup_se...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

SplunkTrust
SplunkTrust

@harsush, please confirm whether your issue is resolved.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma