Splunk Search

How to append data to a lookup without overwriting anything AND also not adding duplicate data entries into the lookup?

Robbie1194
Communicator

Hi guys,

I was wondering if anyone knew of a method of appending data to a lookup, but not overwriting anything in the lookup AND also not adding duplicate data entries into the lookup?

Any suggestions would be helpful.

Cheers,
Robbie

0 Karma
1 Solution

FritzWittwer_ol
Contributor
| inputlookup <table>
| append [makeresults | eval .... | fields - _time]
| dedup <keyfield>
| outputlookup <table> append=false

View solution in original post

comjb
Loves-to-Learn Lots

Another way to do it:

0 Karma

FritzWittwer_ol
Contributor
| inputlookup <table>
| append [makeresults | eval .... | fields - _time]
| dedup <keyfield>
| outputlookup <table> append=false
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...