<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search two lookup tables for matching field values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471313#M132597</link>
    <description>&lt;P&gt;Hi trying to search two lookup tables for matching fields values, both tables have the same fields.&lt;BR /&gt;
Just looking to compare my output UserFromTest1 and UserFromTest2 for a match.&lt;/P&gt;

&lt;P&gt;| inputlookup test1.csv UserName as User OutputNew User as UserFromTest1&lt;BR /&gt;
| inputlookup test2.csv UserName as User OutputNew User as UserFromTest2&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2019 13:03:46 GMT</pubDate>
    <dc:creator>marktechuk</dc:creator>
    <dc:date>2019-09-04T13:03:46Z</dc:date>
    <item>
      <title>Search two lookup tables for matching field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471313#M132597</link>
      <description>&lt;P&gt;Hi trying to search two lookup tables for matching fields values, both tables have the same fields.&lt;BR /&gt;
Just looking to compare my output UserFromTest1 and UserFromTest2 for a match.&lt;/P&gt;

&lt;P&gt;| inputlookup test1.csv UserName as User OutputNew User as UserFromTest1&lt;BR /&gt;
| inputlookup test2.csv UserName as User OutputNew User as UserFromTest2&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 13:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471313#M132597</guid>
      <dc:creator>marktechuk</dc:creator>
      <dc:date>2019-09-04T13:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Search two lookup tables for matching field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471314#M132598</link>
      <description>&lt;P&gt;You need to &lt;CODE&gt;|where&lt;/CODE&gt; after the lookups (and I'd suggest case-insensitivizing it):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;first part of search&amp;gt;
| inputlookup test1.csv UserName as User OutputNew User as UserFromTest1
| inputlookup test2.csv UserName as User OutputNew User as UserFromTest2
| eval UserFromTest2=upper(UserFromTest2)
| eval UserFromTest1=upper(UserFromTest1)
| where UserFromTest2=UserFromTest1
| &amp;lt;rest of search goes here&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471314#M132598</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2019-09-04T14:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Search two lookup tables for matching field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471315#M132599</link>
      <description>&lt;P&gt;| inputlookup Test1.csv &lt;BR /&gt;
 | fields UserName, Count | rename Count as Count1&lt;BR /&gt;
 | join type=inner UserName &lt;BR /&gt;
     [| inputlookup Test2.csv &lt;BR /&gt;
     | fields UserName, Count | rename  Count as count2]&lt;/P&gt;

&lt;P&gt;It will show you the list of UserName's which are present in both the table, i have added count column to show the 2 different count value for the same UserName&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 14:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471315#M132599</guid>
      <dc:creator>rahulbhatia</dc:creator>
      <dc:date>2019-09-04T14:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search two lookup tables for matching field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471316#M132600</link>
      <description>&lt;P&gt;Worked great, thanks &lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2019 18:41:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-two-lookup-tables-for-matching-field-values/m-p/471316#M132600</guid>
      <dc:creator>marktechuk</dc:creator>
      <dc:date>2019-09-04T18:41:24Z</dc:date>
    </item>
  </channel>
</rss>

