Splunk Search

Splunk lookup and scripts

splunkn
Communicator

I am in need of the following requirement. Could anyone help me with this?
I need to extract the users for 200+ applications as a report. For each application, the agent may differ
How to automate this type of report for 200 applications

I need to maintain a lookup table like this
application,agent
abc,123
def,345
efg,456

I need to pass the parameters for application as well as agent in the below query one by one to extract 200 reports
How to do that? Any ideas? Need to do any scripts?
index=* application=abc agent=123 | stats count by user

Tags (2)
0 Karma

kml_uvce
Builder

index=* [|inputlookup lookuptablename|table application] [|inputlookup lookuptablename|table agent]| stats count by user or try this..
index=* [|inputlookup lookuptablename|table application,agent]| stats count by user

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...