Can we create a new field which contains the group of multiple servers name and that field I can use directly in all the query like report, alerts and so I no need to search for the server names all the time and I can just use the created one field directly.
For example index=* sourcetype=* host=X
So here I want to create x=Server A + Server B + Server C.
Is this possible in Splunk ?
Hi @Chirag812 ,
the easiest way to have the same result is to insert the list of servers in a lookup (called e.g. servers.csv) with at least one column (host) and run something like this:
index=* sourcetype=* [ | inputlookup servers.csv | fields host ]
P.S.: when you create this lookup, remember to create also the Lookup Definition.
Ciao.
Giuseppe
Hi @Chirag812 ,
the easiest way to have the same result is to insert the list of servers in a lookup (called e.g. servers.csv) with at least one column (host) and run something like this:
index=* sourcetype=* [ | inputlookup servers.csv | fields host ]
P.S.: when you create this lookup, remember to create also the Lookup Definition.
Ciao.
Giuseppe
Hello Giuseppe,
Thank you for your quick answer. This will definitely be going to help me to achieve this.