Splunk Search

Execute a Search if the condition is met else not

jugalkinariwala
Explorer

Hi Splunkers,

 

I am writing on SPL in the report which has lookup. And if the lookup has less number of rows then overwrite the lookup with existing static lookup.

 

Example:

<myseach>
| outputlookup test1.csv
| stats count
| < if/where condition , where i need to check if the count < 100 , then overwrite existing static lookup into test1.csv else remain as-is"
                         count < 100 , "| inputlookup testlookup.csv | outputlookup test1.csv" , "test1.csv" 


Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...