Splunk Search
Highlighted

How to use time-base-lookup?

Communicator

Hi,Splunk community.

I have a question about time-base-lookup.

I set following attribute to transforms.conf

[test]
collection = test
externaltype = kvstore
fields
list = ip,unit,time
timefield = time
time
format = %d/%m/%y/%H

and I set following attribute to collections.conf.

[test]

Result of "| inputlookup test" is following.

ip time unit
192.168.150.81 09/12/14/18 B部
192.168.150.6 09/12/14/18 A部
192.168.150.81 09/12/14/17 D部
192.168.150.6 09/12/14/17 C部

I search by "index=test | lookup test ip".
However lookup does not work.

Why doesn't work?
Is there a way to solve?

Tags (1)
0 Karma
Highlighted

Re: How to use time-base-lookup?

Contributor

You had it right with "| inputlookup test", just continue your search from there or use the lookup table as enrichment to indexed data. Lookups do no go in the index.

0 Karma
Highlighted

Re: How to use time-base-lookup?

Communicator

Results when I search in "index=test | table _time,ip" are following.

results
_time ip
2014-12-09 18:00:01 192.168.150.81
2014-12-09 18:00:01 192.168.150.81
2014-12-09 18:00:01 192.168.150.6

If lookup correctly works , results when I search "index=test | lookup test ip | table _time,unit,ip" are like following.

results
_time unit ip
2014-12-09 18:00:01 B部 192.168.150.81
2014-12-09 18:00:01 B部 192.168.150.81
2014-12-09 18:00:01 A部 192.168.150.6

However , I don't get the above results.
why can't I get the above result?
Results I get are following

results
_time unit ip
2014-12-09 18:00:01 192.168.150.81
2014-12-09 18:00:01 192.168.150.81
2014-12-09 18:00:01 192.168.150.6

0 Karma
Highlighted

Re: How to use time-base-lookup?

Contributor

Try outputting the field you want from the lookup table, lookup {{tablename}} {{inputfield}} output {{output_field}}

0 Karma
Highlighted

Re: How to use time-base-lookup?

Communicator

dolivasoh,Thank you for your response.

I have tried outputting the field as "index=test | lookup test ip output unit | table _time,unit,ip".

However , I don't get "unit" field.

0 Karma