Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is it possible to do an inputlookup with an OR statement

$
0
0
Hi, I have a query that uses this search to look for hosts that we need to validate: |tstats count WHERE index=* AND [ |inputlookup testSVB2.csv |fields + host] groupby host, index, sourcetype I'd like to expand this, so that it uses additional columns against the host field. I'd have an ip column, and a fqdn name column in the lookup, and then search, comparing those to the hosts field. I'm guessing that an "OR" statement is the best option, but I don't see any way to do that, in this scenario. Does anyone have a suggestion?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>