How to display lookup fields along with search fields.
index=AA* host=ABC source=/tmp/processMonitor* instance=XYZ apphome =*** | lookup boxdata host | search boxlivestate="LIVE" | stats latest(state) as Status by host, apphome, instance, appmon | table host apphome instance appmon boxlivestate
Iam not getting anything under boxlivestate, Is thr any way to display ??
boxenv boxlivestate boxlocation boxmodel boxos boxpatch boxrack boxrfb boxver host
QA NOTLIVE ABC-DE HPXYZQ RHAS 1234 324 lxmcp 6.9 hostny01
host apphome instance appmon Status boxlivestate
ABC /xy/abc abc 1 down Live
@harsush, please reverse the lookup pipe which should be after stats command. In your current query the stats command is removing enriched field/s from lookup including boxlivestate.
index=AA* host=ABC source=/tmp/processMonitor* instance=XYZ apphome =*** | stats latest(state) as Status by host, apphome, instance, appmon | lookup boxdata host | search box_live_state="LIVE" | table host apphome instance appmon box_live_state
Also as per performance consideration, lookup should be performed after transforming commands ensuring records are reduced prior to correlating with the lookup file: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup#Optimizing_your_lookup_se...