<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to include additional field from inputlookup in results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351932#M104154</link>
    <description>&lt;P&gt;Thanks a lot for your replies!&lt;/P&gt;

&lt;P&gt;I receive this error:&lt;/P&gt;

&lt;P&gt;Error in 'rex' command: The regex '(?i)(Error=not starting because the task should|Error=Error getting data)' does not extract anything. It should specify at least one named group. Format: (?...).&lt;/P&gt;</description>
    <pubDate>Sun, 24 Sep 2017 09:52:06 GMT</pubDate>
    <dc:creator>luc_k</dc:creator>
    <dc:date>2017-09-24T09:52:06Z</dc:date>
    <item>
      <title>How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351925#M104147</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a lookup table errors.csv  ,which contains Error and Source columns.I have a query the returns log entries containing Error column values :&lt;/P&gt;

&lt;P&gt;[|inputlookup errors.csv | rename Error AS query | fields query ]&lt;/P&gt;

&lt;P&gt;How do I add the Source column to the results?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Luc  &lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 07:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351925#M104147</guid>
      <dc:creator>luc_k</dc:creator>
      <dc:date>2017-09-20T07:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351926#M104148</link>
      <description>&lt;P&gt;Try this!&lt;/P&gt;

&lt;P&gt;|inputlookup errors.csv &lt;BR /&gt;
|map search="search (your search) \"$Error$\"|eval Error=\"$Error$\", Source=\"$Source$\""&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 14:27:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351926#M104148</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-09-20T14:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351927#M104149</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
as the previous adding lookup command, try something like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your_search [ | inputlookup your_lookup.csv | rename Error AS quesry | fields query ]
| rename _raw as rawText
| eval foo=[
    | inputlookup your_lookup.csv 
    | eval query="%"+Error+"%" 
    | stats values(query) AS query 
    | eval query=mvjoin(query,",") 
    | fields query 
    | format "" "" "" "" "" ""
    ]
| eval foo=split(foo,",") 
| mvexpand foo 
| where like(rawText,foo)
| rex field=foo "\%(?&amp;lt;Error&amp;gt;[^\%]*)\%"
| lookup errors.csv Error OUTPUT Source
| ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 14:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351927#M104149</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-20T14:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351928#M104150</link>
      <description>&lt;P&gt;try this,&lt;/P&gt;

&lt;P&gt;[|inputlookup errors.csv  where Source=* | rename Error AS query | fields query  Source | table query Source]&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 14:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351928#M104150</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2017-09-20T14:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351929#M104151</link>
      <description>&lt;P&gt;@sbbadri - The user didn't say so, but the brackets indicate that this is a subsearch, so this solution will not work.  if Source got passed back at all, it would act as a limit on the main search, rather than giving extra information.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 20:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351929#M104151</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-20T20:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351930#M104152</link>
      <description>&lt;P&gt;@cusello - Not precisely the way I would do it, but it should work for moderate numbers of events and moderate numbers of records in the lookup.  For larger numbers of records, I'd replace the &lt;CODE&gt;mvexpand&lt;/CODE&gt; with a &lt;CODE&gt;rex&lt;/CODE&gt; that pulls out those error values directly, rather than multiplying the number of records.&lt;/P&gt;

&lt;P&gt;Something like this...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; your_search
    [ | inputlookup your_lookup.csv 
    | rename Error AS query 
    | fields query ]
| rex field=_raw [ | inputlookup your_lookup.csv 
    | table Error 
    | sort 0 - Error 
    | rex mode=sed field=Error "s/ /!!!!/g" 
    | format "(?i)(&amp;lt;Error&amp;gt;" "" "" "" "|" ")" 
    | rex mode=sed field=search "s/[ \"]//g s/^\(/\"(/g s/\)$/)\"/g s/!!!!/ /g"]
 | lookup your_lookup.csv Error OUTPUT Source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that this is air code.  I would test that rex-build subsearch with this first, to make sure the regular expression was well formed. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | inputlookup your_lookup.csv 
    | table Error 
    | sort 0 - Error 
    | rex mode=sed field=Error "s/ /!!!!/g" 
    | format "(?i)(&amp;lt;Error&amp;gt;" "" "" "" "|" ")" 
    | rex mode=sed field=search "s/[ \"]//g s/^\(/\"(/g s/\)$/)\"/g s/!!!!/ /g"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Sep 2017 20:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351930#M104152</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-20T20:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351931#M104153</link>
      <description>&lt;P&gt;@HiroshiSatoh - This will work, but I'd only do it for very small numbers of error messages (no more than 10, or at most 20).  &lt;CODE&gt;map&lt;/CODE&gt; is very expensive for what you get.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 20:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351931#M104153</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-20T20:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to include additional field from inputlookup in results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351932#M104154</link>
      <description>&lt;P&gt;Thanks a lot for your replies!&lt;/P&gt;

&lt;P&gt;I receive this error:&lt;/P&gt;

&lt;P&gt;Error in 'rex' command: The regex '(?i)(Error=not starting because the task should|Error=Error getting data)' does not extract anything. It should specify at least one named group. Format: (?...).&lt;/P&gt;</description>
      <pubDate>Sun, 24 Sep 2017 09:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-include-additional-field-from-inputlookup-in-results/m-p/351932#M104154</guid>
      <dc:creator>luc_k</dc:creator>
      <dc:date>2017-09-24T09:52:06Z</dc:date>
    </item>
  </channel>
</rss>

