<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup csv file not producing correct results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497862#M138709</link>
    <description>&lt;P&gt;I really appreciate the help but this did not produce the results I was looking for, unfortunately.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2019 10:49:15 GMT</pubDate>
    <dc:creator>wtaylor149</dc:creator>
    <dc:date>2019-10-04T10:49:15Z</dc:date>
    <item>
      <title>Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497856#M138703</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have a lookup file called fs_src_mac_tg.csv&lt;BR /&gt;
has two columns:&lt;BR /&gt;
&lt;STRONG&gt;src_mac and exists&lt;BR /&gt;
src_mac = a list of mac addresses&lt;BR /&gt;
exists = yes&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex | stats count by src_mac signature | lookup fs_src_mac_tg.csv src_mac OUTPUT exists | fillnull value="no" exists  | search exists="no"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What I'm looking to get is if a mac in the lookup file has not been seen in my search, report that src_mac&lt;/P&gt;

&lt;P&gt;Thanks in advance for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497856#M138703</guid>
      <dc:creator>wtaylor149</dc:creator>
      <dc:date>2020-09-30T02:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497857#M138704</link>
      <description>&lt;P&gt;try appending the lookup instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex | stats count by src_mac signature | inputlookup append=t max=0 fs_src_mac_tg.csv | fillnull value="no" exists |eventstats values(exists) as exists by src_mac| search exists="no"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;you might need to edit it a bit, but by appending it to the bottom, you'll get all results from the lookup, instead of joining the src_mac to the rows that exist from the search.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Inputlookup"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Inputlookup&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Lookup"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 20:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497857#M138704</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2019-10-03T20:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497858#M138705</link>
      <description>&lt;P&gt;How about this?  It looks in myindex with src_mac not in the lookup file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex NOT [|inputlookup fs_src_mac_tg.csv | fields src_mac | format]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 Oct 2019 20:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497858#M138705</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-10-03T20:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497859#M138706</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=myindex | stats count by src_mac signature
| eval which="data"
| inputlookup append=true fs_src_mac_tg.csv src_mac
| eval which=coalesce(which, "lookup")
| stats values(*) AS * dc(which) AS which_count BY src_mac
| where which_count==1 AND which="lookup"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 04 Oct 2019 02:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497859#M138706</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-04T02:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497860#M138707</link>
      <description>&lt;P&gt;Thanks for the reply.  Unfortunately this did not work.  Even errored out on the "src_mac" after the lookup.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 10:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497860#M138707</guid>
      <dc:creator>wtaylor149</dc:creator>
      <dc:date>2019-10-04T10:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497861#M138708</link>
      <description>&lt;P&gt;Thanks for the reply but this also did not produce the results.  This search seems like it should work.  I want to search for only the src_mac listed in the lookup, if a src_mac is not found show me the src_mac.  Seemed simple.  Thanks again for helping.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497861#M138708</guid>
      <dc:creator>wtaylor149</dc:creator>
      <dc:date>2020-09-30T02:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497862#M138709</link>
      <description>&lt;P&gt;I really appreciate the help but this did not produce the results I was looking for, unfortunately.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 10:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497862#M138709</guid>
      <dc:creator>wtaylor149</dc:creator>
      <dc:date>2019-10-04T10:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497863#M138710</link>
      <description>&lt;P&gt;I think I was making this way more complicated than it had to be.  The below search worked perfect.  Thanks again for all the help.  By far Splunk folks are the best and willing to help out.&lt;/P&gt;

&lt;P&gt;index=myindex | stats count as status by src_mac | inputlookup append=true src_mac.csv | stats max(status) as status by src_mac | fillnull value="not_found" | search status="not_found"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:28:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497863#M138710</guid>
      <dc:creator>wtaylor149</dc:creator>
      <dc:date>2020-09-30T02:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup csv file not producing correct results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497864#M138711</link>
      <description>&lt;P&gt;Yup, it would.  I fixed the answer.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 12:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-csv-file-not-producing-correct-results/m-p/497864#M138711</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-10-04T12:39:24Z</dc:date>
    </item>
  </channel>
</rss>

