My log snippet is as shown below:
productid=12 email=abc@gg.com
productid=13 email=pqr@aa.com
productid=14 email=xyz@cc.com
I want to show "Product1" for 12 & "Product2" for 13 & "Product3" for 14 in the legends in my timechart.
/
productid,product_desc
12,Product1
13,Product2
/
[product_lookup]
filename = product_lookup.csv
/
[product_lookup]
LOOKUP-product_desc = product_lookup productid OUTPUT product_desc
After restarting server, when I'm running below query, it does not show product_desc.
index=myindex sourcetype=mylog | timechart count by product_desc
Can any one tell me why its not showing any output? How to use transforms/props, etc??
Any help is much appreciated!
Thanks!
What is the sourcetype for your log? In props.conf, you have
[product_lookup]
LOOKUP-product_desc = product_lookup productid OUTPUT product_desc
But the stanza name should be your sourcetype as below:
[yourSourcetypeName]
LOOKUP-product_desc = product_lookup productid OUTPUT product_desc
Also, is there a field named productid
in your log file?
What is the sourcetype for your log? In props.conf, you have
[product_lookup]
LOOKUP-product_desc = product_lookup productid OUTPUT product_desc
But the stanza name should be your sourcetype as below:
[yourSourcetypeName]
LOOKUP-product_desc = product_lookup productid OUTPUT product_desc
Also, is there a field named productid
in your log file?
If you can, use the Manager UI in Splunk to set up your lookups. Then you can see what Splunk writes to the configuration files...
I've used UI to generate these files. I don't want to write anything in csv file...Basically, I'm keeping my mapping in it & I want to read it from my query. Can you please tell me why its now showing up in my search result?
The configuration files for "props" and "transforms" should have ".conf" as the end of the filename, not ".csv". If that was merely a typo in your question here, I'd start looking at the results of searches before the timechart call, to ensure that the lookup is happening before that.
Its a typo...I've corrected it. Can you please help?