Splunk Search

Join results from two lookups

shaquibk
Explorer

My requirement is something like this:

Lookup 1 looks like this

Name | Avg_Count
A          | 3
B          |  7
D          | 8
F           | 5

Lookup 2 looks like this:

Name | Current_Count
A          | 2
C          | 4
D          | 6

In the search, I input both these lookups and want results like this:
Name | Avg_Count | Current_count
A          | 3                     | 2
B          | 7                     | 0/null (0 preferred)
D          | 8                     | 6
F          | 5                      | 0
C         | 0                      | 4

I have tried join/append/appendcols but all these have their limitations and won't give the intended results. Also looked at many solutions from community but couldn't find one.

Thanks in advance!

Shaquib

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| inputlookup lookup1
| append [| inputlookup lookup2]
| stats values(*) as * by Name
| fillnull value=0

View solution in original post

0 Karma

shaquibk
Explorer

Thanks @ITWhisperer and  @gcusello 

Both the solutions were accurate and worked perfectly. Appreciate the prompt response too.

Thanks and Regards,

Shaquib

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @shaquibk,

with append command you should have the results you need:

| inputlookup lookup1
| append [ | inputlookup lookup1 | fields Name Current_Count ]
| stats values(Avg_Count) AS Avg_Count values(Current_Count) AS Current_Count BY Name

If you have more numbers for Avg_Count or Current_Count, instead values use another option in the stats command (e.g. max or sum).

Ciao.

Giuseppe

ITWhisperer
SplunkTrust
SplunkTrust
| inputlookup lookup1
| append [| inputlookup lookup2]
| stats values(*) as * by Name
| fillnull value=0
0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...