Splunk Search

Splunk lookup and scripts

splunkn
Communicator

I am in need of the following requirement. Could anyone help me with this?
I need to extract the users for 200+ applications as a report. For each application, the agent may differ
How to automate this type of report for 200 applications

I need to maintain a lookup table like this
application,agent
abc,123
def,345
efg,456

I need to pass the parameters for application as well as agent in the below query one by one to extract 200 reports
How to do that? Any ideas? Need to do any scripts?
index=* application=abc agent=123 | stats count by user

Tags (2)
0 Karma

kml_uvce
Builder

index=* [|inputlookup lookuptablename|table application] [|inputlookup lookuptablename|table agent]| stats count by user or try this..
index=* [|inputlookup lookuptablename|table application,agent]| stats count by user

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...