Splunk Search

Where/Search clause does not work with lookup.

sherwin_r
Explorer

I am  having trouble comparing the columns age and expectedAge, where the column expectedAge is a result of a lookup table. I tried the comparison with "where" as well as "search" clauses. Neither of them worked. I just simply want to select the rows where age > expectedAge.

Expected behaviour :

Return rows where the above mentioned condition is met.

 

Actual behaviour :

Returns nothing.

 

| eval age=bla..bla..bla 
| lookup "expected_age_lookup" dummy_s as s OUTPUT expected_age
| fillnull value=777 expected_age
| rename expected_age as expectedAge
| search age > expectedAge
| convert ctime(dummy_Time) 
| table age,s,dummy_Time,expectedAge

 

 

If I remove the lines following (and including) the where/search clause, I see the results of the lookup. 

How can I achieve this correctly ?

Labels (1)
0 Karma

sherwin_r
Explorer

The data is complete in my case, because they are evaluated fields. One thing to note is that The column age is in a float format and expectedAge is in int format (Atleast looks like that).

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The fact that you are using eval is expected but does not help identify where the problem is, please share your data (anonymised where appropriate).

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The where command should work assuming your data is consistent with the condition, i.e. both fields hold numerics. If it is still not working, please share your data (anonymised where appropriate).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...