Dashboards & Visualizations

Why is outputlookup not updating to store search results?

supraja
Path Finder

Hi Team,

 

i want store the query results in lookup file  , but outputlookup  command is not updating the csv as per results set .

 

index = ........ queryresults ............|  outputlookup test.csv 

 

is there any changes required  in the query ?

 

 

regards,

supraja

 

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Do you have permissions to update the lookup?

0 Karma

supraja
Path Finder

Hi , 

 

its already tried 

 

index = ............
| fields  ............
|where clause ...........
|table <fileds>
|outputlookup test.csv

0 Karma

MYilmaz
Explorer

Hi @supraja 

can you try the search below.

index=.... 
table ....
|outputlookup append=true yourfile.csv
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...