Splunk Search

Use saved search (reports) as lookup

Path Finder

I have a savedsearch (reports) that i want to use as lookup, it is possible?
Should i use it as subsearch?

0 Karma
1 Solution

Path Finder

you can save the output of the saved search to a lookup using the OUTPUTLOOKUP command

| (your search | outputlookup (your lookup)

View solution in original post

Path Finder

you can save the output of the saved search to a lookup using the OUTPUTLOOKUP command

| (your search | outputlookup (your lookup)

View solution in original post

Path Finder

It works! Thanks

0 Karma

SplunkTrust
SplunkTrust

It is possible? Probably. Should you? Maybe
Please tell us more about your use case and the saved search you want to use as a lookup.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Path Finder

The savedsearch returns only one column "ALIAS" with about 200 records (ex. AAA001- AAA002- AAA003- etc.)
In the panel (from dashboard) i have a table with two columns: ALIAS and CHECK.
ALIAS CHECK
AAA001 NO
BBB001 NO
CCC001 NO
, etc. , etc.

So whit lookup i would like intercept ALIAS and when this matches with savedsearch, returns OK:
ALIAS CHECK
AAA001 OK
BBB001 NO
CCC001 NO
, etc. , etc.

0 Karma