<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup table help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410954#M118568</link>
    <description>&lt;P&gt;Hi picaresqu3,&lt;BR /&gt;
try something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=nwk action=allowed protocol=TCP
 | top dest_port
 | lookup port_descriptions.csv port AS dest_port OUTPUT description
 | rename dest_port AS "Destination Port" count AS "Hits" percent AS "Percent of Top 10" description AS Description
 | table "Destination Port" Description Hits "Percent of Top 10"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2019 11:16:59 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-07-31T11:16:59Z</dc:date>
    <item>
      <title>Lookup table help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410953#M118567</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Still learning the ropes here, but am making some dashboards and could use some help with a lookup table. I have a panel that gives me the top 10 used ports leaving my router. Would like to match the dest_port with a description for what runs on said port, which is contained in the lookup csv.&lt;/P&gt;

&lt;P&gt;I've imported my CSV into Splunk (port_descriptions.csv) and it has 3 colums: protocol, port, description&lt;/P&gt;

&lt;P&gt;Here is a quick shot of what it looks like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;protocol    port    description
TCP         0   Reserved
TCP         1   Port Service Multiplexer
TCP         2   Management Utility
TCP         3   Compression Process
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my current search, &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=nwk AND action=allowed AND protocol=TCP
| top dest_port
| rename dest_port AS "Destination Port"
| rename count AS "Hits"
| rename percent AS "Percent of Top 10"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've tried adding the following, but it seems to give me different results than the original search above. Not sure if i should also have the search map the protocol, too?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| lookup port_descriptions.csv port AS dest_port
| top dest_port by description
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Anyway, if you've come this far, thanks for reading and trying to help a noobie out.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 01:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410953#M118567</guid>
      <dc:creator>picaresqu3</dc:creator>
      <dc:date>2019-07-31T01:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410954#M118568</link>
      <description>&lt;P&gt;Hi picaresqu3,&lt;BR /&gt;
try something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=nwk action=allowed protocol=TCP
 | top dest_port
 | lookup port_descriptions.csv port AS dest_port OUTPUT description
 | rename dest_port AS "Destination Port" count AS "Hits" percent AS "Percent of Top 10" description AS Description
 | table "Destination Port" Description Hits "Percent of Top 10"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 11:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410954#M118568</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-31T11:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410955#M118569</link>
      <description>&lt;P&gt;@gcusello thank you! I was getting duplicates in the description field since the CSV had TCP and UDP entries, but I just broke them out into 2 separate lookup table files to fix. Thank you! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 15:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410955#M118569</guid>
      <dc:creator>picaresqu3</dc:creator>
      <dc:date>2019-07-31T15:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup table help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410956#M118570</link>
      <description>&lt;P&gt;Hi picaresqu3,&lt;BR /&gt;
if this answer helped you, please accept and/or upvote it.&lt;BR /&gt;
Bye, see next time.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 17:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-table-help/m-p/410956#M118570</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-31T17:33:27Z</dc:date>
    </item>
  </channel>
</rss>

