I am trying to integrate a lookup into a search with no success. My goal is to run the search, lookup the hostname or TID and compare it to the lookup table (HOSTNAME field) and return results based on matches to the ROLE field. The ROLE column in the lookup that defines whether TID is core, cpe or aggregation. Here is my search:
index=my_main "SFP receive power low alarm set"
| stats dc(date_mday) as Days, count by TID, J_Port | eval c_TID=upper(c_TID)
| where Days > 2 AND count > 49 | appendpipe [stats count | where count=0]
| rename count as "Total Errors", TID as Hostname, J_Port as Port
| sort -"Total Errors"
The lookup table file and definition are working. My difficulty is integrating it into my search.
... View more