<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Creating Field from Inputlookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527190#M148812</link>
    <description>&lt;P&gt;Hello.&lt;BR /&gt;I'm trying to create a field for all events in a search. The field is a value from a inpulookup. There is no shared fields between the lookup and the search in the conventional sense. The organization of my lookup is as follows&lt;/P&gt;&lt;P&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; email1 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; email2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; email3&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex2@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex3@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex4@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex5@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex6@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex7@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex8@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex9@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex10@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex11@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex12@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;|inputlookup email.csv
            | search ID = "1"
            | strcat email1", " email2", " email3 emails
            | table emails&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;The above searches gives me my desired output of&lt;BR /&gt;emails=&lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com,&amp;nbsp;&lt;/A&gt;&lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com&lt;/A&gt;, &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I pop in into an eval statement to give each event that field/value I get an error about a malformed eval.&lt;/P&gt;&lt;P&gt;Below is the eval I am trying to do.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=main (insert search here)
|eval test =[|inputlookup email.csv
            | search ID = "1"
            | strcat email1", " email2", " email3 emails
            | return $emails
            ]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated. Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2020 00:46:15 GMT</pubDate>
    <dc:creator>TooManyQuestion</dc:creator>
    <dc:date>2020-10-30T00:46:15Z</dc:date>
    <item>
      <title>Creating Field from Inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527190#M148812</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;I'm trying to create a field for all events in a search. The field is a value from a inpulookup. There is no shared fields between the lookup and the search in the conventional sense. The organization of my lookup is as follows&lt;/P&gt;&lt;P&gt;ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; email1 &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; email2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; email3&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex2@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex3@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex4@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex5@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex6@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex7@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex8@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex9@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp; &amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex10@gmail..com&lt;/A&gt; &amp;nbsp; &amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex11@gmail..com&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex12@gmail..com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;|inputlookup email.csv
            | search ID = "1"
            | strcat email1", " email2", " email3 emails
            | table emails&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;The above searches gives me my desired output of&lt;BR /&gt;emails=&lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com,&amp;nbsp;&lt;/A&gt;&lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com&lt;/A&gt;, &lt;A href="mailto:ex1@gmail..com" target="_blank" rel="noopener"&gt;ex1@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I pop in into an eval statement to give each event that field/value I get an error about a malformed eval.&lt;/P&gt;&lt;P&gt;Below is the eval I am trying to do.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=main (insert search here)
|eval test =[|inputlookup email.csv
            | search ID = "1"
            | strcat email1", " email2", " email3 emails
            | return $emails
            ]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 00:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527190#M148812</guid>
      <dc:creator>TooManyQuestion</dc:creator>
      <dc:date>2020-10-30T00:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Field from Inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527196#M148815</link>
      <description>&lt;P&gt;Try&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main (insert search here)
|eval [|inputlookup email.csv
            | search ID = "1"
            | strcat email1 ", " email2 ", " email3 emails
            | return emails
            ]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 02:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527196#M148815</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-10-30T02:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Field from Inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527197#M148816</link>
      <description>&lt;P&gt;Thanks! That got me there! I knew I was just messing up something small and couldn't work it out.&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=main (insert search here)
|eval [|inputlookup email.csv
            | search ID = "1"
            | strcat email1 ", " email2 ", " email3 emails
            | return emails
            ]&lt;/LI-CODE&gt;&lt;P&gt;Just had to remove the emails before the subsearch otherwise it gave me "emails emails" as the field name!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 02:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527197#M148816</guid>
      <dc:creator>TooManyQuestion</dc:creator>
      <dc:date>2020-10-30T02:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Field from Inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527198#M148817</link>
      <description>&lt;P&gt;Yes, removed extra field. My bad, I forgot that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 02:57:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527198#M148817</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-10-30T02:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Field from Inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527203#M148819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp;/ all,&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main | eval [|inputlookup ..... |return emails]&lt;/LI-CODE&gt;&lt;P&gt;for SPL newbies, could someone explain this "eval" part, thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Sekar&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 04:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Creating-Field-from-Inputlookup/m-p/527203#M148819</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-30T04:09:04Z</dc:date>
    </item>
  </channel>
</rss>

