<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WILDCARD in LookUp .csv files in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511901#M143541</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224431"&gt;@boromir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you try the below,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to Lookup definition --&amp;gt; Advanced options --&amp;gt; Match Type, and enter&amp;nbsp;WILDCARD(FieldName)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FieldName - The field which consists of wild card in the lookup file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check and let me know if you still come across any issues.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2020 09:06:36 GMT</pubDate>
    <dc:creator>Kwip</dc:creator>
    <dc:date>2020-07-31T09:06:36Z</dc:date>
    <item>
      <title>WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511898#M143540</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a challenge, that i have been struggling for the past few days, and can't find the correct solution.&lt;/P&gt;&lt;P&gt;I have read&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Can-we-use-wildcard-characters-in-a-lookup-table/td-p/94513" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Can-we-use-wildcard-characters-in-a-lookup-table/td-p/94513&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and done pretty much exactly the same thing, but it doesn't work for me. So here are the details.&lt;/P&gt;&lt;P&gt;I have a simple lookup csv file (2 columns ), first one with starting digits&lt;/P&gt;&lt;P&gt;&lt;EM&gt;prefix, state&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;23401*, log1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;23402*,log2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;34602*,log5&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;....etc&lt;/P&gt;&lt;P&gt;I have used the GUI to create the lookup definitions, but i have also double-cheked transformes.conf and props.conf. It is exactly as in the example in the link. I can't make the wildcard work for me.&lt;/P&gt;&lt;P&gt;Here is a simple search line just to illustrate&lt;/P&gt;&lt;P&gt;&lt;EM&gt;source="log2.log" host="prod-splunk-indexer" sourcetype="testsource" |&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;lookup prefixlookup.csv prefix OUTPUT state | &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;table prefix state&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If i create lookup with exact matches, it works for the match everytime, however, my client requires only prefixchecks, and to me WILDCARD is the only solution.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;PS.&lt;/P&gt;&lt;P&gt;I have actually created exact replica of the case(user,username, userlookup, etc) in the linked example, still doesn't work&lt;/P&gt;&lt;P&gt;Have a great day!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 08:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511898#M143540</guid>
      <dc:creator>boromir</dc:creator>
      <dc:date>2020-07-31T08:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511901#M143541</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224431"&gt;@boromir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you try the below,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Go to Lookup definition --&amp;gt; Advanced options --&amp;gt; Match Type, and enter&amp;nbsp;WILDCARD(FieldName)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FieldName - The field which consists of wild card in the lookup file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check and let me know if you still come across any issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 09:06:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511901#M143541</guid>
      <dc:creator>Kwip</dc:creator>
      <dc:date>2020-07-31T09:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511908#M143543</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for responding:)&lt;/P&gt;&lt;P&gt;Exacltly the same. I feel like I am missing something. I can't even make the example work.&lt;/P&gt;&lt;P&gt;As mentioned, I am now fighting to make the example from the link to work, and have completely put my put my case on the backburner. So here is what i have , and doesn't work:&lt;/P&gt;&lt;P&gt;userlookup.csv&lt;/P&gt;&lt;P&gt;&lt;EM&gt;user,username&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;user*,USERNAME&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;transforms.conf&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[userlookup]&lt;BR /&gt;batch_index_query = 0&lt;BR /&gt;case_sensitive_match = 1&lt;BR /&gt;filename = userlookup.csv&lt;BR /&gt;match_type = WILDCARD(user)&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Props.conf&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[log2]&lt;BR /&gt;LOOKUP-user = userlookup user OUTPUT username&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;...&lt;/EM&gt;And for the full picture :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="boromir_0-1596187725351.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9979i72100F4959C51622/image-size/medium?v=v2&amp;amp;px=400" role="button" title="boromir_0-1596187725351.png" alt="boromir_0-1596187725351.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that the solution is in front of my eyes, but I fail to see it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 09:29:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511908#M143543</guid>
      <dc:creator>boromir</dc:creator>
      <dc:date>2020-07-31T09:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511915#M143546</link>
      <description>&lt;P&gt;Can you elaborate your requirement a bit more,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you want to filter your results with the prefix field values in the csv and again assign a state field value to the results?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If above is your requirement, try the below query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source="log2.log" host="prod-splunk-indexer" sourcetype="testsource" prefix=*
    [| inputlookup prefixlookup.csv 
    | table prefix] 
| lookup prefixlookup.csv prefix OUTPUT state 
| table prefix state&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 11:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/511915#M143546</guid>
      <dc:creator>Kwip</dc:creator>
      <dc:date>2020-07-31T11:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/512113#M143617</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks, I will try to explain it better.&lt;/P&gt;&lt;P&gt;My client provides me a table(csv 1000x lines , 2 columns) with prefixes that I will be able to find in the logs from the monitored equipment. Based on those prefixes, I have to structure them, assign them new values, which we will use later. Based on what I have read, Lookup with wildcard in the lookup table is the solution to my challenge, and based on &lt;A href="https://community.splunk.com/t5/Splunk-Search/Can-we-use-wildcard-characters-in-a-lookup-table/td-p/94513" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Can-we-use-wildcard-characters-in-a-lookup-table/td-p/... &lt;/A&gt;&lt;/P&gt;&lt;P&gt;I should be able to get exactly what i need, however , it still doesn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested your example, but it gets me exactly the same result. The wildcard does not match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 10:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/512113#M143617</guid>
      <dc:creator>boromir</dc:creator>
      <dc:date>2020-08-03T10:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: WILDCARD in LookUp .csv files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/512326#M143694</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi all,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I have to say , I found the issue that was bugging me. As suggested, it was something simple , that was in front of me all the time.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Here is what didn't work:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;sourcetype="log2" | lookup ranges.csv comment OUTPUT state&amp;nbsp; | table comment state&lt;/P&gt;&lt;P class="lia-align-justify"&gt;And here is what worked:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;sourcetype="log2" | lookup ranges comment OUTPUT state&amp;nbsp; | table comment state&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I can't believe I didn't figure it out earlier, but hey, learning is a process &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 10:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/WILDCARD-in-LookUp-csv-files/m-p/512326#M143694</guid>
      <dc:creator>boromir</dc:creator>
      <dc:date>2020-08-04T10:06:54Z</dc:date>
    </item>
  </channel>
</rss>

