Splunk Search

How to add inputlookup file in the query

Harish2
Path Finder

Hi ,
I have uploaded the lookupfile with application host and hostip details in the splunk.

i am not sure where to add this inputlookup file so that when i run this query i should get application details.
when i run this query i am getting only _time and ClientName  responsetime data, i need application details as well.

My Query:

index=app_cust_ctl sourcetype=applicationdata
|bin _time span=1s
|rex "\d{2}:\d{2}:\d{2}:\d{3} (?<responsetime>;\d+) ms"
|stats count(eval(Status="success")) as sucessapp, count(eval(Status="error")) as errorapp, avg(responsetime) as appresponsetime, max(responsetime) as maxresponsetime by _time application ClientName

|eval record="location"




Labels (1)
0 Karma
1 Solution
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...