Splunk Search

How to append the result of a search to values of a multivalued field?

buttsurfer
Path Finder

 

I have a SPL search that returns a field with multiple values (names of lookups). I want to concat the lookup name and it's origin app, found with the search below:

      | rest splunk_server=local /servicesNS/-/-/saved/searches | table title eai:acl.app eai:acl.owner search | where match(search,"outputlookup\s+lookupname")

 

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could try something like this

| rex max_match=0 field=search "outputlookup\s+(?<lookup>.+)"
| eval lookups=mvjoin(mvappend(title,lookup)," ")
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are two problems with the query.  The first is the table command is removing the lookupname field so there is nothing for match to look for.  The second is Splunk has two concatenation operators: + and . (dot).  IME, dot works better.

| rest splunk_server=local /servicesNS/-/-/saved/searches 
| eval lookupname="incident_settings" 
| eval matchstring="outputlookup\s"+lookupname 
| table title eai:acl.app eai:acl.owner search lookupname 
| where match(search,"outputlookup\s" . lookupname)

A word of caution: the lookup name may not be the first word after outputlookup if the command uses options like append or create_empty.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...