Splunk Search

Use saved search (reports) as lookup

splunk6161
Path Finder

I have a savedsearch (reports) that i want to use as lookup, it is possible?
Should i use it as subsearch?

0 Karma
1 Solution

chinmoya
Communicator

you can save the output of the saved search to a lookup using the OUTPUTLOOKUP command

| (your search | outputlookup (your lookup)

View solution in original post

chinmoya
Communicator

you can save the output of the saved search to a lookup using the OUTPUTLOOKUP command

| (your search | outputlookup (your lookup)

splunk6161
Path Finder

It works! Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It is possible? Probably. Should you? Maybe
Please tell us more about your use case and the saved search you want to use as a lookup.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunk6161
Path Finder

The savedsearch returns only one column "ALIAS" with about 200 records (ex. AAA001- AAA002- AAA003- etc.)
In the panel (from dashboard) i have a table with two columns: ALIAS and CHECK.
ALIAS CHECK
AAA001 NO
BBB001 NO
CCC001 NO
, etc. , etc.

So whit lookup i would like intercept ALIAS and when this matches with savedsearch, returns OK:
ALIAS CHECK
AAA001 OK
BBB001 NO
CCC001 NO
, etc. , etc.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...