Hi , I have uploaded the lookupfile with application host and hostip details in the splunk. i am not sure where to add this inputlookup file so that when i run this query i should get application details. when i run this query i am getting only _time and ClientName responsetime data, i need application details as well. My Query: index=app_cust_ctl sourcetype=applicationdata |bin _time span=1s |rex "\d{2}:\d{2}:\d{2}:\d{3} (?<responsetime>;\d+) ms" |stats count(eval(Status="success")) as sucessapp, count(eval(Status="error")) as errorapp, avg(responsetime) as appresponsetime, max(responsetime) as maxresponsetime by _time application ClientName |eval record="location"
... View more