Splunk Search

How to automatically initiate second search using the results of the first search

Itsecuser1
New Member

index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | sort - count | where count > 100

I would get results of 5 users and i want to initiate a different search using the results ,  can you let me know how i can do it 

index=logs   appname="appname  " user="here i need those 5 user names  found in the results to be inserted   "    url=*somewebsitenamestring   |   table _time user url  

I would prefer to receive 5 individual csv files for each user rather than one file with all 5 user data.

 

Thanks for your help , please let me know if this is possible 

 

 

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=logs   appname="appname url=*somewebsitenamestring   
 [ search index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | where count > 100 | table user ]
|   table _time user url
  
0 Karma

Itsecuser1
New Member

Thanks a lot , i am able to view the results of the  user  , but i am not able to see a statistics table sorted by the user with the highest  count  , please can you let me know if it is possible to display the table 

Also is it possible to generate a CSV file for each individual user with the highest count ( higher than 100)  as part of an alert or as a report 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=logs   appname="appname url=*somewebsitenamestring   
 [ search index=logs  appname="nameofapp " url=somewebsitenamestring     |  stats count by user | where count > 100 | table user ]
| eventstats count by user
| sort -count
| table _time user url count

I don't think you can generate a csv file for each user, you can generate a csv file but it would contain all the results.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...