Splunk Search

How to add inputlookup and outputlookup in same search

Communicator

Hi!

I would like to know if it is possible to add outputlookup and inputlookup in same search.
My purpose is to create a table dynamically and use it in other sub searches.

I thought this can be possible by using subsearches but bit struggling with it.

index=hoge
[ sub search
outputlookup
return ""
]
[ | inputlookup xxxxx]

but alsways the inputlookup runs before the outputlookup.

Any suggestions ?

Thanks,
Yu

Tags (2)
0 Karma

Explorer

eventtype=snowcmdbcilist | dedup sysid | fields - bkt, _cd,indextime,kv,raw,serial,si,sourcetype,subsecond, punct, index, source, sourcetype | inputlookup append=t cmdbcilistlookup | dedup sysid | outputlookup cmdbcilist_lookup

0 Karma

Legend

Subsearches always run before the outer searches, as for the order in which subsearches themselves run I don't think there's a guaranteed order for that.

Please tell us more about exactly what you want to accomplish, with examples.

Explorer

Found one such example from Splunk Add-on for ServiceNow :

eventtype=snowcmdbcilist | dedup sysid | fields - bkt, _cd,indextime,kv,raw,serial,si,sourcetype,subsecond, punct, index, source, sourcetype | inputlookup append=t cmdbcilistlookup | dedup sysid | outputlookup cmdbcilist_lookup

0 Karma