Splunk Query

Hi Guys,

i have observed different output 

in action "Execute Splunk query" if query is beginning with | pipe output is accurate 

| inputlookup data.csv | head 5

and if without | pipe result is different 

inputlookup data.csv | head 5

Any idea why?

Solved Solved
0 1 194
1 ACCEPTED SOLUTION

It's my understanding any time you want Splunk to execute a command in search, you'll put a "|" before the command. So without the pipe in your 2nd search, I believe it's searching for the string "inputlookup data.csv" rather than actually running the "inputlookup" command. 

-mike

View solution in original post

1 REPLY 1

It's my understanding any time you want Splunk to execute a command in search, you'll put a "|" before the command. So without the pipe in your 2nd search, I believe it's searching for the string "inputlookup data.csv" rather than actually running the "inputlookup" command. 

-mike