Apologies, I am quite new to Splunk so not sure if this is possible, I have the following simple query: | inputlookup appJobLogs
| where match(MessageText, "(?i)general e...
Hi I cross the results of a subsearch with a main search like this index=toto [inputlookup test.csv |eval user=Domain."\\"Sam |table user] |table _time user Imagine I need to add a new lookup i...
Hello Splunkers,
Please if someone can help me with a Splunk query,
I have a list of IPs I imported in lookup table, I want to grab the FW traffic where dest_ip in the FW logs matches my lookup l...
I have 2 lookup files as lookup1.csv and lookup2.csv lookup1.csv has the data as below name, designation, server, ipaddress, dept
tim, ceo, hostname.com, 1.2.3.5, alldept
jim, vp, myhost.com, 1...
...2 NOT ([ inputlookup FP_malware.csv]) | eval time=strftime(_time,"%Y-%m-%d %H:%M:%S")|stats count by time hip hdn etdn p2 | dedup p2
it seems not working . So how can i fix this ????? Many t...
...ecause the agent has not been installed yet or because I report logs and at a certain point I stop doing it I installed the "lookup Editor" and already uploaded the inventory there. Using the query | inputlookup...
I setup testing.csv lookup as following host,location 123,HK 234,US 345,UK
I would like to basic search if host matched in the log, stats count by location index=log sourcetype=csv |search [|inputlookup...