Splunk Search
Highlighted

Why isn't my search showing the full results?

Communicator

When I search for this query it shows wrong results ?

|metadata type=hosts index=* |lookup domain.csv host output domain datacenter host IP |search domain=Y|eval age=(now()-recentTime)|convert ctime(*Time)| append[ |inputlookup domain.csv ] | dedup host | fields host IP domain datacenter lastTime age totalCount| sort lastTime

When I serach for this query shows full results ?

host=wdc |stats count by host

Any help .

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

SplunkTrust
SplunkTrust

When you coded this...

| lookup domain.csv host output domain datacenter host IP 

I suspect you may have meant this...

| lookup domain.csv host OUTPUT domain datacenter host IP 
0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Communicator

Iam not sure why the metadata search is not showing full results .

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Communicator

I dont see any change after changing Capital OUTPUT .

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Legend

Hi splunker969
did you tried

| metasearch index=* 
| lookup domain.csv host OUTPUT domain datacenter host IP 
| search domain=Y 
| eval age=(now()-recentTime) 
| convert ctime(*Time) 
| append [ |inputlookup domain.csv ] 
| dedup host 
| fields host IP domain datacenter lastTime age totalCount
| sort lastTime

?
Anyway in your search there is something strange: you append a lookup rows (without date/time field) to a search with date/time and then you perform a dedup by host (deleting in this way some results maybe with time and age) and then you sort results by lastTime that it isn't in the lookup, what do you want as result?

Bye.
Giuseppe

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Communicator

Actually we are trying to right above search with logging list and not logging list to be in same list .So we used that above search.

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Communicator

Thanks @ cusello

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Splunk Employee
Splunk Employee

Hey @splunker969, if they solved your problem, remember to "√Accept" an answer to award karma points 🙂

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Communicator

sure , .@ ifedak ,the problem was not resolved .Thanks 🙂

0 Karma
Highlighted

Re: Why isn't my search showing the full results?

Motivator

try this
metadata type=hosts index=* |lookup domain.csv host OUTPUTNEW domain datacenter host IP |eval test=if(domain=="Y", "Logging In", "Not Logging In") |eval age=(now()-recentTime)|convert ctime(*Time)| append[ |inputlookup domain.csv ] | dedup host | fields host IP domain datacenter lastTime age test
totalCount| sort lastTime

0 Karma