Splunk Search

Lookup table: provide the field twice for the same event

KarunK
Contributor

Hi,

I am doing a lookup for classifying the "location" of servers using host-name using props.conf. But when i am doing the search i am getting the location fields more than once for a each event. Hence when I count for the events by location, i am getting always twice the actual count.

Props.conf

[cds_cdsmpoll]
LOOKUP-cds_cdsmpoll = cds_address hostname OUTPUT location as LOCATION

Has any one seen this behaviour before ?

Tags (1)
0 Karma

Drainy
Champion

Do you have the hostname field showing more than once within an event? E.g. somewhere there is an alias to change host to hostname as well as a field extraction for hostname within the event. This would result in the location field being produced twice.

Also I haven't tested this but maaybe its possible its because you are changing the name to an upper case version. Have you tested it without the as LOCATION ? This is just a rename function, it should work without the final as conversion.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...