Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

finding lookup table hits

$
0
0

I have a whitelist of IP in a lookup table - say LT.csv :: [column name whiteip]

I have a search string say "Search String"

An extracted field called "ipaddress".

I want to generate a report, how many ip from my lookuptable are visible in splunk search result.


Can you help with the query:

"Search String" ["inputlookup LT.csv | fields whiteip] AND "whiteip" = "ipaddress" | stats count by "whiteip"


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>