Splunk Search

Extracting fields from look up file & calculating each field count

Communicator

Hi,
I am having a lookup csv file, I have uploaded it in Automatic lookup's with Application=ApplicationName & ServerName=host
Application_Name & host are listed in fields.
CSV file is as below

Application, Server_Name

App1, server1
App1, Server2
App1, Server3
App1, Server4
App2, Server2
App2, Server5
App2, Server6
App2, Server7

..| append [inputlookup serverslookup] | search Application="App1" | chart count over ServerName by Status
If I use the above command, I am getting the below output

Server count

server1 1
Server2 1
Server3 1
Server4 1

But If I run the query with host instead of Server_Name

Server count

server1 11
Server2 23
Server3 42
Server4 8
Which is actaul count.

Could you please help me to get the correct result by using lookfield

0 Karma
1 Solution

Communicator

Ooo, Worked now, Problem with the case sensitive....

View solution in original post

0 Karma

Communicator

Ooo, Worked now, Problem with the case sensitive....

View solution in original post

0 Karma