<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup with hundreds values for one field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505738#M141396</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions" target="_self"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This question is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no query&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions&lt;/A&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Have you seen the reference?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 13:14:47 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-06-23T13:14:47Z</dc:date>
    <item>
      <title>Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505594#M141298</link>
      <description>&lt;P&gt;Still new to Splunk, seeking for some help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a index=account_Information, with account_number, cell_number, etc.&amp;nbsp; &amp;nbsp; I want to list the account_number and the cell_number associated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a list of hundreds account_numbers in a csv file. I uploaded the csv file but how to use it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;My search:&amp;nbsp; &amp;nbsp;(how to replace the ORs)&lt;/P&gt;&lt;P&gt;index=account_Information &lt;STRONG&gt;account_Number_1 OR&amp;nbsp;account_Number_2 OR account_number_3 ...&amp;nbsp;&lt;/STRONG&gt; |&amp;nbsp; table account_number cell_number&lt;/P&gt;&lt;P&gt;Thanks a lot. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 19:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505594#M141298</guid>
      <dc:creator>gaok123</dc:creator>
      <dc:date>2020-06-22T19:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505595#M141299</link>
      <description>You have both an index with account information and a CSV with account information. What do you want to do with them? What problem are you trying to solve?&lt;BR /&gt;Have you looked at the 'lookup' command?</description>
      <pubDate>Mon, 22 Jun 2020 19:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505595#M141299</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-22T19:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505636#M141359</link>
      <description>&lt;P&gt;Thanks for reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a raw data index=account_information.&amp;nbsp; &amp;nbsp;In the raw data, each entry has fields such as&amp;nbsp; &amp;nbsp;account_number, cell_number, customer_name, address, product, etc. The raw data has (let's say) a million entries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to search several hundred customer's cell_number, by the known account_number. I copied accont_number in a csv file and uploaded. wandering how to use the csv.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will look into "lookup".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 02:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505636#M141359</guid>
      <dc:creator>gaok123</dc:creator>
      <dc:date>2020-06-23T02:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505725#M141389</link>
      <description>Again, I'm not seeing the problem. You already have cell_number in the index so why bother with the CSV file?</description>
      <pubDate>Tue, 23 Jun 2020 12:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505725#M141389</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-23T12:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505728#M141390</link>
      <description>&lt;P&gt;The problem is I have hundreds account_number. I want a single search for these hundreds result.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 12:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505728#M141390</guid>
      <dc:creator>gaok123</dc:creator>
      <dc:date>2020-06-23T12:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505736#M141395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222835"&gt;@gaok123&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please try running following search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face="georgia,palatino"&gt;index=account_Information | table account_number cell_number&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;after this, you can manipulate your records &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Upvote if it helps&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt; !!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 13:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505736#M141395</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2020-06-23T13:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505738#M141396</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions" target="_self"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This question is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no query&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions&lt;/A&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Have you seen the reference?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 13:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505738#M141396</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-06-23T13:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505758#M141403</link>
      <description>&lt;P&gt;O, Yes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the sample log as My_Log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[13/Mar/2018:18:24:02] Account_ID=5036 Code=B Cell_Number=6024298300471575 18767&lt;BR /&gt;[13/Mar/2018:18:23:46] Account_ID=7026 Code=C Cell_Number=8702194102896748 13876&lt;BR /&gt;[13/Mar/2018:18:23:31] Account_ID=1043 Code=B Cell_Number=2063718909897951 12345&lt;BR /&gt;[13/Mar/2018:18:22:59] Account_ID=1243 Code=C Cell_Number=8768831614147676 34466&lt;BR /&gt;[13/Mar/2018:18:21:02] Account_ID=4536 Code=B Cell_Number=6024298300471575 34676&lt;BR /&gt;[13/Mar/2018:18:20:46] Account_ID=2367 Code=C Cell_Number=54019g3677596748 87765&lt;BR /&gt;[13/Mar/2018:18:19:31] Account_ID=4146 Code=B Cell_Number=9476648906654451 15123&lt;BR /&gt;[13/Mar/2018:18:18:59] Account_ID=3467 Code=B Cell_Number=1038675849147346 25343&lt;/P&gt;&lt;P&gt;I'm interested in cell_number, input is Account_ID, few hundreds of them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To search a single result, I can use&lt;/P&gt;&lt;P&gt;Index=My_log&amp;nbsp;Account_ID=5036 | table Account_ID Cell_Number&lt;/P&gt;&lt;P&gt;To search two result, I can use&lt;/P&gt;&lt;P&gt;Index=My_log&amp;nbsp;Account_ID=5036 &lt;STRONG&gt;OR&lt;/STRONG&gt; Account_ID=4146 | table Account_ID Cell_Number&lt;/P&gt;&lt;P&gt;My question is how to search hundreds Account_Id at one shot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I though I can use a csv file. So I uploaded accountId.csv with one column as Account_ID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample of accountId.csv&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;Account_ID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;5036&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;1243&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;&amp;nbsp;4146&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried following , didn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=My_log | stats count by Cell_Number | lookup accountId.csv Account_ID output Account_ID | table Cell_Number&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope above examples explain me well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank a lot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 15:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505758#M141403</guid>
      <dc:creator>gaok123</dc:creator>
      <dc:date>2020-06-23T15:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505786#M141416</link>
      <description>&lt;P&gt;The examples help a lot.&amp;nbsp; I believe you can use a subsearch to do what you want.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_log [ | inputlookup accountId.csv | fields Account_ID | format ]
| table Account_ID Cell_Number&lt;/LI-CODE&gt;&lt;P&gt;The subsearch reads the CSV file and formats the results into&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(Account_ID=5036) OR (Account_ID=4146) , etc.&lt;/LI-CODE&gt;&lt;P&gt;which becomes part of the main search and should get you just a few hundred results.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 17:25:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505786#M141416</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-23T17:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup with hundreds values for one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505802#M141425</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;index=My_log 
| stats count by Account_ID Cell_Number 
| lookup accountId.csv Account_ID output Account_ID as foundme
| where Account_ID = foundme
| table Account_ID Cell_Number&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;P&gt;1) You have to keep all the fields you need in the &lt;STRONG&gt;stats&lt;/STRONG&gt; command somehow, or they will not exist afterwards.&lt;/P&gt;&lt;P&gt;2) When you output the lookup results, you need to give it a new name or you won't know whether it was found or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 17:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-with-hundreds-values-for-one-field/m-p/505802#M141425</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-06-23T17:59:37Z</dc:date>
    </item>
  </channel>
</rss>

