<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem in Lookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43568#M10234</link>
    <description>&lt;P&gt;when I am seperately doing the below command : &lt;/P&gt;

&lt;P&gt;|inputlookup "Full_CDI.csv"&lt;/P&gt;

&lt;P&gt;then all the data I am getting as my result set&lt;/P&gt;

&lt;P&gt;Please suggest !!&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2013 13:03:48 GMT</pubDate>
    <dc:creator>abhayneilam</dc:creator>
    <dc:date>2013-02-26T13:03:48Z</dc:date>
    <item>
      <title>Problem in Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43566#M10232</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am getting the below message when I am using lookup&lt;/P&gt;

&lt;P&gt;my command .... | lookup "Full_CDI.csv" user_sso&lt;/P&gt;

&lt;P&gt;Empty csv lookup file (contains only a header) for table 'Full_CDI.csv': C:\Program Files\Splunk\etc\apps\search\lookups\Full_CDI.csv&lt;/P&gt;

&lt;P&gt;I have around 5,91,662 Data in my Full_CDI.csv file, but still I am not getting any data as a output , all the fileds are coming blank in the result set in SPLUNK but data is present in the CSV file..&lt;/P&gt;

&lt;P&gt;Suggest me any solution for this !!&lt;BR /&gt;
Thanks in Advance !!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43566#M10232</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2020-09-28T13:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43567#M10233</link>
      <description>&lt;P&gt;What does the output look like if you run:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup "Full_CDI.csv"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Make sure the csv is in UTF-8 and not ANSI, and is not just a poorly formatted excel document.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 11:52:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43567#M10233</guid>
      <dc:creator>SplunkFu</dc:creator>
      <dc:date>2013-02-26T11:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem in Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43568#M10234</link>
      <description>&lt;P&gt;when I am seperately doing the below command : &lt;/P&gt;

&lt;P&gt;|inputlookup "Full_CDI.csv"&lt;/P&gt;

&lt;P&gt;then all the data I am getting as my result set&lt;/P&gt;

&lt;P&gt;Please suggest !!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 13:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-in-Lookup/m-p/43568#M10234</guid>
      <dc:creator>abhayneilam</dc:creator>
      <dc:date>2013-02-26T13:03:48Z</dc:date>
    </item>
  </channel>
</rss>

