Hello everyone.
The scenario:
The question:
Is there any way to avoid this scenario, i.e. have Splunk web be non-destructive to the saved search stanzas? Or could this be considered a bug?
Thanks,
Noah
noahzstahl,
I would think this is a bug. We should not be overwriting the entire stanza. As a workaround you can use the inputlookup
and outputlookup
search commands to generate the lookup file instead of savedsearches.conf settings. This allows you to achieve everything via search syntax.
Example of a descructive output each time:
search = index=_internal | stats count by host, sourcetype | outputlookup my_lookup_table
To do a non-descructive lookup (useful when tracking stuff):
search = index=_internal | stats count by host, sourcetype | inputlookup append=T my_lookup_table | stats sum(count) as count by host, sourcetype | outputlookup my_lookup_table
-David
noahzstahl,
I would think this is a bug. We should not be overwriting the entire stanza. As a workaround you can use the inputlookup
and outputlookup
search commands to generate the lookup file instead of savedsearches.conf settings. This allows you to achieve everything via search syntax.
Example of a descructive output each time:
search = index=_internal | stats count by host, sourcetype | outputlookup my_lookup_table
To do a non-descructive lookup (useful when tracking stuff):
search = index=_internal | stats count by host, sourcetype | inputlookup append=T my_lookup_table | stats sum(count) as count by host, sourcetype | outputlookup my_lookup_table
-David
Thanks David. I like the idea of including everything in the search string.