Splunk Search

I cannot find data in field named version in my request?

chimell1
Explorer

I cannot find data in field named version in my request. Please help me.See request belong

 

|mstats min(cpu_metric.pctIdle) as val WHERE `itsi_entity_type_ta_nix_metrics_indexes` AND CPU="all" by host span=1m |eval val=100-val|lookup Serveurs-applications-Document-travail.csv "Nom du serveur" AS host OUTPUTNEW Version

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Examine the lookup file (Serveurs-applications-Document-travail.csv) using the Lookup File Editor app or the inputlookup command. Verify you have the correct field name in your query.

---
If this reply helps you, Karma would be appreciated.

chimell1
Explorer

What is Lookup File Editor app??

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's the old name for the Splunk App for Lookup File Editing app (https://splunkbase.splunk.com/app/1724).  If you don't have it on your system, use the inputlookup command.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...