Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to combine foreach command with lookup data?

$
0
0
Hello, In order to clean our filtering rules we'd like to check if some of our old URL's are still in use (an if yes - how many times in last 90 days). Basically we'd like to perform the query below: index=nginx sourcetype="nginx:plus:access" | search uri_path= | stats count The problem is that there are almost 600 URL's we need to check. We'd like to know if there is a way to put all the URL's in a lookup and then perform a kind of `foreach` search. Thanks for the help. Alex.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>