I have index with json data that represents call data (phone calls), but there is nothing native in the index that represents lists.
Assume, for example, I have a list called "Splunk Legends" and it represents 10 numbers.
Currently if I want to 'count all calls last 30d from Splunk Legends, then I do
index=mydata
| stats value(*) by guid -- because I'm joining some other interesting information in this index
| lookup mylookup.csv number OUTPUT list
| search list="Splunk Legends"
What I dislike about this, of course, is I have to search the entire index.
Thoughts on a better way to match value against an external data source?
Thank you!
Try incorporating the lookup into the base search.
index=mydata [ | inputlookup mylookup.csv where list="Splunk Legends" | fields number | format ]
| stats value(*) by guid -- because I'm joining some other interesting information in this index
...
Try incorporating the lookup into the base search.
index=mydata [ | inputlookup mylookup.csv where list="Splunk Legends" | fields number | format ]
| stats value(*) by guid -- because I'm joining some other interesting information in this index
...
thoughts on the 10k limit using sub searches like this? just ran into that.
Legend. Thank you!