<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I combine multiple lookups into one lookup? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540251#M152822</link>
    <description>&lt;P&gt;Is there a way to use "foreach" to add the flag and append?&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 14:05:45 GMT</pubDate>
    <dc:creator>Glasses</dc:creator>
    <dc:date>2021-02-17T14:05:45Z</dc:date>
    <item>
      <title>How do I combine multiple lookups into one lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540141#M152783</link>
      <description>&lt;P&gt;Lets say I have 3 lookups &amp;gt;&amp;gt;&amp;gt; a-list.csv, b-list.csv, c-list.csv and the lists only have 1 column header = Name&lt;BR /&gt;Alice is on a-list&lt;BR /&gt;Bob is on b-list&lt;BR /&gt;Charles is on c-list&lt;/P&gt;&lt;P&gt;There are lots of people on each list and the lists are dynamic and updated.&lt;BR /&gt;I have a request to create a Combined_Master Lookup (where C_M-list.csv = a-list.csv + b-list.csv + c-list.csv),&lt;BR /&gt;where the list contains NAME, FLAG fields such as&lt;/P&gt;&lt;P&gt;NAME,FLAG&lt;/P&gt;&lt;P&gt;Alice, a-list&lt;BR /&gt;Bob, b-list&lt;BR /&gt;Charles, c-list&lt;/P&gt;&lt;P&gt;So far I use the following query to build the C_M-list.csv, where there is a Name and Flag appended to each name (which indicate which list the person is from)&lt;BR /&gt;BUT I am wondering if there is a better way...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup a-list.csv 
| eval FLAG = "a-list"
| inputlookup b-list.csv append=true
| eval FLAG = coalesce(FLAG, "b-list") 
| inputlookup c-list.csv append=true
| eval FLAG = coalesce(FLAG, "c-list")
|.... &amp;lt;rest of the query follows&amp;gt;....&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My desired outcome is a M_C-list.csv&lt;/P&gt;&lt;P&gt;Alice,a-list&lt;/P&gt;&lt;P&gt;Bob,b-list&lt;/P&gt;&lt;P&gt;Charles,c-list&lt;/P&gt;&lt;P&gt;Any suggestions or improvements appreciated.&lt;BR /&gt;TY!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 19:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540141#M152783</guid>
      <dc:creator>Glasses</dc:creator>
      <dc:date>2021-02-16T19:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine multiple lookups into one lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540251#M152822</link>
      <description>&lt;P&gt;Is there a way to use "foreach" to add the flag and append?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:05:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540251#M152822</guid>
      <dc:creator>Glasses</dc:creator>
      <dc:date>2021-02-17T14:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine multiple lookups into one lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540267#M152829</link>
      <description>&lt;P&gt;Greetings&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/138497"&gt;@Glasses&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;           | inputlookup a-list.csv 
           | eval FLAG = "a-list"

| append [ | inputlookup b-list.csv
           | eval FLAG = "b-list" ]

| append [ | inputlookup c-list.csv
           | eval FLAG = "c-list" ]&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 17 Feb 2021 15:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540267#M152829</guid>
      <dc:creator>jacobpevans</dc:creator>
      <dc:date>2021-02-17T15:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine multiple lookups into one lookup?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540268#M152830</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/182087"&gt;@jacobpevans&lt;/a&gt;&amp;nbsp;NICE!!!&lt;/P&gt;&lt;P&gt;I tried something similar with subsearches and failed... but this seems like they way to go.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 15:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-multiple-lookups-into-one-lookup/m-p/540268#M152830</guid>
      <dc:creator>Glasses</dc:creator>
      <dc:date>2021-02-17T15:38:12Z</dc:date>
    </item>
  </channel>
</rss>

