Splunk Search

lookup multi value

ChetanArgekar
Explorer

I have multiple devices in a given location maintaining it lookup table with location and device.

Using location from index I am trying to get device list but output is coming in single row. I want list of devices as separate row. How to achieve it.

My query is like this

index =myindex

| lookup mylookup location OUTPUT devices 

| table devices

 

Labels (2)
0 Karma
1 Solution

ChetanArgekar
Explorer

Solved.

index = myindex

| lookup mylookup location OUTPUT devices 

| stats count(devices) by location, devices

| table devices 

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ChetanArgekar,

please, try something like this:

index =myindex
| append [ | inputlookup mylookup | fields location devices ]
| stats values(devices) AS devices by location
| mvexpand devices

Ciao.

Giuseppe

0 Karma

ChetanArgekar
Explorer

thanks

It is giving only one device of location. I want list of every device of the location in separate row

0 Karma

ChetanArgekar
Explorer

Solved.

index = myindex

| lookup mylookup location OUTPUT devices 

| stats count(devices) by location, devices

| table devices 

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...