<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ingest_eval lookup example in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/538313#M90236</link>
    <description>Hi, do you know what made it work for you? I get the same WARN message, but not the error and I think my configuration is similar. I tried placing the lookup file in both the app and system/lookup directory on my indexers.</description>
    <pubDate>Tue, 02 Feb 2021 17:16:06 GMT</pubDate>
    <dc:creator>tah7004</dc:creator>
    <dc:date>2021-02-02T17:16:06Z</dc:date>
    <item>
      <title>ingest_eval lookup example</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/534975#M89745</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to ingest data using a lookup like descripted in:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/IngestLookups" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Data/IngestLookups&lt;/A&gt;&lt;/P&gt;&lt;P&gt;props.conf:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[ilookuptest]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TRANSFORMS-a&lt;/SPAN&gt;&lt;SPAN&gt; = ilookuptest1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;TRANSFORMS-b&lt;/SPAN&gt;&lt;SPAN&gt; = ilookuptest2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;transforms.conf:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[ilookuptest1]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;INGEST_EVAL&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;pod&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"testpod1"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[ilookuptest2]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;INGEST_EVAL&lt;/SPAN&gt;&lt;SPAN&gt;= &lt;/SPAN&gt;&lt;SPAN&gt;annotation&lt;/SPAN&gt;&lt;SPAN&gt;=lookup(&lt;/SPAN&gt;&lt;SPAN&gt;"testlookup.csv"&lt;/SPAN&gt;&lt;SPAN&gt;, json_object(&lt;/SPAN&gt;&lt;SPAN&gt;"pod"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"pod"&lt;/SPAN&gt;&lt;SPAN&gt;), json_array(&lt;/SPAN&gt;&lt;SPAN&gt;"annotation"&lt;/SPAN&gt;&lt;SPAN&gt;)) &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;lookup testlookup.csv:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;pod,annotation&lt;BR /&gt;testpod1,testannotation1&lt;BR /&gt;testpod2,testannotation2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ingest data using:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;curl -k &lt;A href="http://192.168.208.5:8088/services/collector" target="_blank"&gt;http://192.168.208.5:8088/services/collector&lt;/A&gt; -H 'Authorization: Splunk f05eedbb-a706-427e-9606-baa3e8036411' -d '{"index": "test", "sourcetype": "ilookuptest", "event":"this is for testing ingest eval lookup12"}&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;props.conf and transforms.conf are located at $SPLUNK_HOME/etc/system/local .. lookup at $SPLUNK_HOME/etc/system/lookups .&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I'm getting errors&amp;nbsp; in splunkd.log:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;WARN&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CsvDataProvider&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;No&lt;/SPAN&gt; &lt;SPAN class="t"&gt;valid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;lookup&lt;/SPAN&gt; &lt;SPAN class="t"&gt;table&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;SPAN class="t"&gt;this&lt;/SPAN&gt; &lt;SPAN class="t"&gt;lookup=testlookup&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t h"&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CsvDataProvider&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;The&lt;/SPAN&gt; &lt;SPAN class="t"&gt;lookup&lt;/SPAN&gt; &lt;SPAN class="t"&gt;table&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;testlookup&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;does&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exist&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;is&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;available.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t h"&gt;ERROR&lt;/SPAN&gt; pipeline - Runtime exception in pipeline=typing processor=regexreplacement error='Invalid function argument' confkey='source::http:test|host::192.168.208.5:8088|ilookuptest|'&lt;BR /&gt;&lt;SPAN class="t h"&gt;ERROR&lt;/SPAN&gt; pipeline - Uncaught exception in pipeline execution (regexreplacement) - getting next event&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;The event is not indexed...&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When defining transforms.conf&lt;BR /&gt;&lt;SPAN&gt;INGEST_EVAL&lt;/SPAN&gt;&lt;SPAN&gt;= &lt;/SPAN&gt;&lt;SPAN&gt;annotation&lt;/SPAN&gt;&lt;SPAN&gt;=lookup(&lt;/SPAN&gt;&lt;SPAN&gt;"testlookup"&lt;/SPAN&gt;&lt;SPAN&gt;, json_object(&lt;/SPAN&gt;&lt;SPAN&gt;"pod"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;"pod"&lt;/SPAN&gt;&lt;SPAN&gt;), json_array(&lt;/SPAN&gt;&lt;SPAN&gt;"annotation"&lt;/SPAN&gt;&lt;SPAN&gt;)) &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I'm getting errors in splunkd.log:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t h"&gt;WARN&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CsvDataProvider&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Unable&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;find&lt;/SPAN&gt; &lt;SPAN class="t"&gt;filename&lt;/SPAN&gt; &lt;SPAN class="t"&gt;property&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;SPAN class="t"&gt;lookup=testlookup.csv&lt;/SPAN&gt; &lt;SPAN class="t"&gt;will&lt;/SPAN&gt; &lt;SPAN class="t"&gt;attempt&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;use&lt;/SPAN&gt; &lt;SPAN class="t"&gt;implicit&lt;/SPAN&gt; &lt;SPAN class="t"&gt;filename.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Event is indexed but not getting the value from the lookup.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;File is there, read permissions are set, "| inputlookup testlookup.csv" is displaying results.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Any hints or a working INGEST_EVAL using lookups example?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Best Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Andreas&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 06 Jan 2021 17:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/534975#M89745</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2021-01-06T17:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: ingest_eval lookup example</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/535501#M89806</link>
      <description>&lt;P&gt;a working transforms.conf:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[ilookuptest1]&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;INGEST_EVAL&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;pod&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"testpod1"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[ilookuptest2]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;INGEST_EVAL&lt;/SPAN&gt;&lt;SPAN&gt;= &lt;/SPAN&gt;&lt;SPAN&gt;annotation&lt;/SPAN&gt;&lt;SPAN&gt;=json_extract(lookup(&lt;/SPAN&gt;&lt;SPAN&gt;"testlookup.csv"&lt;/SPAN&gt;&lt;SPAN&gt;,json_object(&lt;/SPAN&gt;&lt;SPAN&gt;"pod"&lt;/SPAN&gt;&lt;SPAN&gt;,pod), json_array(annotation)),&lt;/SPAN&gt;&lt;SPAN&gt;"annotation"&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;message:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t h"&gt;WARN&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;CsvDataProvider&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;Unable&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;to&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;find&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;filename&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;property&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;for&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;lookup=testlookup.csv&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;will&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;attempt&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;to&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;use&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;implicit&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;filename.&lt;BR /&gt;&lt;BR /&gt;still there, but working.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;Andreas&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Jan 2021 15:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/535501#M89806</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2021-01-12T15:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: ingest_eval lookup example</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/538313#M90236</link>
      <description>Hi, do you know what made it work for you? I get the same WARN message, but not the error and I think my configuration is similar. I tried placing the lookup file in both the app and system/lookup directory on my indexers.</description>
      <pubDate>Tue, 02 Feb 2021 17:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/ingest-eval-lookup-example/m-p/538313#M90236</guid>
      <dc:creator>tah7004</dc:creator>
      <dc:date>2021-02-02T17:16:06Z</dc:date>
    </item>
  </channel>
</rss>

