Splunk Search

How can I iterate through this lookup by the 'no' field and display each entry as a result?

arunkuriakose
Explorer

Hi 

 

I have a lookup which looks like this

no  name     student     rollno

1      john           yes           12

2       George     no             2345

3      jin                yes          111

 

How can i iterate through this lookup by the 'no' field and display each entry as a result . I only need one result at a time

so when i first run the search the result should be

no  name     student     rollno

1      john           yes           12

 

When i run the same search after a minute the result should be

 

no  name     student     rollno

2       George     no             2345

 

 

Please help

Labels (2)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

There are not many ways to store and retrieve state between searches.  One idea is to use an auxiliary lookup file.  Let's call it displayed.csv.

| inputlookup mylookup
| lookup displayed.csv no OUTPUT rollno AS displayed
| where isnull(displayed)
| sort no
| head 1
| outputlookup append=true displayed.csv

Lookup displayed.csv must be set up before hand, to the destination outputlookup will write into.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...