I have an inputlookup called hosts.csv that looks like this:
host ---------- hostname1 hostname2 hostname3 hostname4
I want to list all indexes containing the value of host in raw data against that hostname. So the output I am looking for is...
host index ------------------------------ hostname1 firewall web unix proxy hostname2 firewall database unix dmz hostname3 firewall proxy hostname4 firewall proxy windows
I have tried using the search below which gives me matching indexes containing the hostnames in raw data. But I am not able to create a table to list the hostnames against the indexes.
[|inputlookup hosts.csv|table host|rename host as search|format]|stats values(index)
I tried adding
code...|lookup hosts.csv host OUTPUT host| stats values(index) by host and get no results. Can you please help me obtain the output above?
Yes they match, even though they are part of an fqdn I can see them in raw data when I query for them using
...|rename host as search|format.
Also splunk produces a list of matching indices when I use the query
[|inputlookup hosts.csv|table host|rename host as search|format]|stats values(index).
I just am struggling to append the index list with the hostnames from the lookup.