Splunk Search

Splunk lookup and scripts

splunkn
Communicator

I am in need of the following requirement. Could anyone help me with this?
I need to extract the users for 200+ applications as a report. For each application, the agent may differ
How to automate this type of report for 200 applications

I need to maintain a lookup table like this
application,agent
abc,123
def,345
efg,456

I need to pass the parameters for application as well as agent in the below query one by one to extract 200 reports
How to do that? Any ideas? Need to do any scripts?
index=* application=abc agent=123 | stats count by user

Tags (2)
0 Karma

kml_uvce
Builder

index=* [|inputlookup lookuptablename|table application] [|inputlookup lookuptablename|table agent]| stats count by user or try this..
index=* [|inputlookup lookuptablename|table application,agent]| stats count by user

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...