![]() ![]() How do i write a query so that it searches all the strings individually and later when i do a stats gives me a occurance count of each string. The inputlookup command is a command to list the contents of a lookup. This command works by turning search results into lookup tables so that the data can be retrieved later using an inputlookup command. (Too many open files) OR (CPU Starvation detected) OR (: Cannot obtain connection:) OR (thread(s) in total in the server that may be hung) Hi darphboubou, in few words: the lookup command is a join betweeen the main search and the lookup, using the defined key. OctoWhat is outputlookup in Splunk The outputlookup command is a way to save any search you’ve made as a lookup table. then, i search field1 in a lookup with a column with file names like this: lookup wheretosearch. In the first lookup i have the name of the files to search: I have a query with field names on a column like this: field1 name1 name2. When i run |inputlookup search_string.csv | return 15 $search_string Hi, Ive been trying to use the output from a lookup as input to another lookup. My intention is to create a logic to use the lookup file so that in a rare event if there are any changes/addition/deletion to the query strings, no one touches the actual query, just a change/addition/deletion in the lookup file would be enough. I have already saved these queries in a lookup csv, but unable to reference the lookup file to run the query ![]() Index=abc sourcetype=xyz "field_name" |stats count by field_name My requirement is to save these strings in a field and then run a query like Too many open files, CPU Starvation detected, : Cannot obtain connection, thread(s) in total in the server that may be hung, Trust Association Init Error, problems occurred during startup for, OutOfMemoryError) I have a list of query strings (these are just strings not a field) I have a requirement that is somewhat similar: ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |