Splunk Search

Splunk lookup and scripts

splunkn
Communicator

I am in need of the following requirement. Could anyone help me with this?
I need to extract the users for 200+ applications as a report. For each application, the agent may differ
How to automate this type of report for 200 applications

I need to maintain a lookup table like this
application,agent
abc,123
def,345
efg,456

I need to pass the parameters for application as well as agent in the below query one by one to extract 200 reports
How to do that? Any ideas? Need to do any scripts?
index=* application=abc agent=123 | stats count by user

Tags (2)
0 Karma

kml_uvce
Builder

index=* [|inputlookup lookuptablename|table application] [|inputlookup lookuptablename|table agent]| stats count by user or try this..
index=* [|inputlookup lookuptablename|table application,agent]| stats count by user

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...