Splunk Search

How to update only the last row of a table lookup dynamically

lufermalgo
Path Finder

Hello community,

I have a lookup cn two fields, _time and count per day. I need to update each time the record of the current day without affecting the previous days as the days can not see again.

alt text

0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

your current search to get the count and ran for today i.e. earliest=@d latest=now | timechart span=1d count 
| inputlookup yourlookup.csv append=t | stats max(count) as count by _time | outputlookup yourlookup.csv

So, every time you run this search for time range today, it will recalculate count for today, merge it with current lookup values and takes the highest count for today (every day but since you're updating today's count only, remaining day's count will remain unchanged), which should be higher in the latest run.

View solution in original post

gokadroid
Motivator

Try this:

|inputlookup yourCsvOrLookupTableFileName append=t
|append [ search yoursearch that gets you the values the way in screenshot | tail 1 ]
| outputlookup yourCsvOrLookupTableFileName

Example for me was:

  |inputlookup ipVal.csv append=t 
  |append [search index=main sid="grass" |mySearch| tail 1 ]
  | outputlookup ipVal.csv

somesoni2
Revered Legend

Try like this

your current search to get the count and ran for today i.e. earliest=@d latest=now | timechart span=1d count 
| inputlookup yourlookup.csv append=t | stats max(count) as count by _time | outputlookup yourlookup.csv

So, every time you run this search for time range today, it will recalculate count for today, merge it with current lookup values and takes the highest count for today (every day but since you're updating today's count only, remaining day's count will remain unchanged), which should be higher in the latest run.

Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...