Training + Certification Discussions

Fundamentals1_m12 Module 12 of Splunk Fundamentals

michaelcarnett
Engager

On page 2 of the of this module it has you creating a lookup table file and then a Lookup definition.

When you successfully create the table file and try to create a definition that points to that CSV the file is missing from the drop down menu.

From the search I had to enter "|inputlookup products.csv" which displayed the contents of products.csv and then when I went back to the definition creation I could select products.csv from the lookup file selection.

Hope this helps someone else.

Elmwoodie
Engager

I couldnt get the auto lookup working  no matter what I did on page 3    😞

Couldnt see fields Price or ProductName .  Not sure what I was doing wrong.

index=main sourcetype="access_combined_wcookie" file=success.do status=200 | stats sum(Price) as Revenue by ProductName

 

Elmwoodie_0-1591915157201.png

 

 

 

0 Karma

ricardoutrilla
Engager

thanks a lot, the exact same thing happened to me, your post just saved me a lot of google search & dig

training_222
Engager

Thank you.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hi @michaelcarnett,

Can you please share sample XML? I think the problem might be in fieldvalue & fieldLabel option of dropdown.
Thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...