Splunk Search

Splunk lookup and scripts

splunkn
Communicator

I am in need of the following requirement. Could anyone help me with this?
I need to extract the users for 200+ applications as a report. For each application, the agent may differ
How to automate this type of report for 200 applications

I need to maintain a lookup table like this
application,agent
abc,123
def,345
efg,456

I need to pass the parameters for application as well as agent in the below query one by one to extract 200 reports
How to do that? Any ideas? Need to do any scripts?
index=* application=abc agent=123 | stats count by user

Tags (2)
0 Karma

kml_uvce
Builder

index=* [|inputlookup lookuptablename|table application] [|inputlookup lookuptablename|table agent]| stats count by user or try this..
index=* [|inputlookup lookuptablename|table application,agent]| stats count by user

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...