How would I display the following data which is part of CSV file? I am looking for a command to do that. top is not working, I can't think of other commands to display
503 Service unavailable
406 Not Acceptable Client
400 Bad Request Error
408 Request Timeout
500 Internal Server Error
404 Page Not Found
I want blank values for 505 and 403 to be displayed so that I can try fillnull command.
thanks you for your estimate!
Anyway the solution is the one hinted by @vnravikumar: if you already have loaded your csv in a lookup (called e.g. ws_codes.csv) you can use it in three ways using two commands
inputlookup and lookup:
| inputlookup ws_codes.csv;
index=my_index [ | inputlookup ws_codes.csv | fields Code] | ...;
to enrich a search result with the content of the lookup, adding e.g. Description that isn't present in the search result:
| lookup ws_codes.csv Code AS your_Code_field OUTPUT Description
| table _time my_fields Cods Description
You can find infos on these commands at https://docs.splunk.com/Documentation/Splunk/8.0.1/SearchReference/Inputlookup and https://docs.splunk.com/Documentation/Splunk/8.0.1/SearchReference/Lookup .
If instead you still haven't loaded the csv in the lookup you have to follow two ways:
In both cases, remember to create a Lookup Definition [Settings -- Lookups -- Lookup definition -- Add new].
Ciao and Happy New Year.
@gcusello Actually, I didn't want to use lookup.
I am so stupid but later figured it how simple it is.
Just upload the file as I am an Administrator on my machine. Then use head or table commands. then use fillnull value=whatevervalue.
Thank you again. Hope you had a wonderful Christmas