Splunk Search

How to multisearch using values from more than one lookup?

amitrinx
Explorer

I have two lookups
ID-RL-Quotas: Endpoint, Endpoint Name, filter, quota, Window
ID-RL-Filters: Attribute, filter

I want to loop through all the endpoints. all endpoints have a specific window, quota and filter and i am searching it based on filter attribute
I want output fields Endpoint Name, filter, Quota

This is the query i came up with

| inputlookup ID-RL-Quotas | lookup ID-RL-Filters Filter | fields Endpoint, "Endpoint Name", Attribute, Window, Quota, Filter | rename "Endpoint Name" as EndpointName
| map [| eval Window = tonumber($Window$) | search sourcetype="oxygen-standard"
http_url = "$Endpoint$"
minutesago=Window
| eval ip = mvindex(split(http_remoteip,","),0)
| eval EndpointName = "$EndpointName$"
| eval WindowI ="$Window$"
| eval QuotaI="$Quota$"
| eval FilterI="$Filter$"
| search $Attribute$ = "*"
| stats values(EndpointName) as "Endpoint Name", values(FilterI) as Filter, values(WindowI) as Window, values(QuotaI) as Quota, count by $Attribute$
| where count >= 0.8 * $Quota$
| sort -count] maxsearches=10000

This only gives me one filter output not all

Labels (2)
Tags (2)
0 Karma

PickleRick
Ultra Champion

Firstly, the topic says "multisearch" and you're using map.

Secondly, you don't have any event-generating commands in your map.

Thirdly, most probably this isnot the way to solve your problem.

0 Karma
Get Updates on the Splunk Community!

Don't wait! Accept the Mission Possible: Splunk Adoption Challenge Now and Win ...

Attention everyone! We have exciting news to share! We are recruiting new members for the Mission Possible: ...

Unify Your SecOps with Splunk Mission Control

In today’s post, I'm excited to share some recent Splunk Mission Control innovations. With Splunk Mission ...

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...