<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search for IDS with inputlookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545551#M154554</link>
    <description>&lt;P&gt;So this may be a pretty easy task, however I am not getting it to work the way I want it:&lt;BR /&gt;&lt;BR /&gt;so here is my problem:&lt;BR /&gt;&lt;BR /&gt;I have CSV with 3 columns&lt;BR /&gt;id,uid,role&lt;BR /&gt;1,2342334,master&lt;BR /&gt;2,2342334,slave&lt;BR /&gt;3,34234234,master&lt;BR /&gt;(...)&lt;BR /&gt;&lt;BR /&gt;Now I want a search on my index that returns me all data where the uid is in the csv.&lt;BR /&gt;What I did so far is the following :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index =&amp;nbsp;myindex&amp;nbsp;[ |inputlookup mycsv.csv&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;| fields 10000 $uid ]&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="inherit"&gt;However this solution is not perfect.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="inherit"&gt;What&amp;nbsp;&lt;/FONT&gt;I&lt;FONT face="inherit"&gt;&amp;nbsp;&lt;/FONT&gt;would&lt;FONT face="inherit"&gt;&amp;nbsp;wanted to achieve should be like this&lt;BR /&gt;index=&amp;nbsp;&lt;/FONT&gt;myindex uid=2342334 or uid =34234234 or uid=(..)&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Mar 2021 10:39:25 GMT</pubDate>
    <dc:creator>Aaron283</dc:creator>
    <dc:date>2021-03-26T10:39:25Z</dc:date>
    <item>
      <title>Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545551#M154554</link>
      <description>&lt;P&gt;So this may be a pretty easy task, however I am not getting it to work the way I want it:&lt;BR /&gt;&lt;BR /&gt;so here is my problem:&lt;BR /&gt;&lt;BR /&gt;I have CSV with 3 columns&lt;BR /&gt;id,uid,role&lt;BR /&gt;1,2342334,master&lt;BR /&gt;2,2342334,slave&lt;BR /&gt;3,34234234,master&lt;BR /&gt;(...)&lt;BR /&gt;&lt;BR /&gt;Now I want a search on my index that returns me all data where the uid is in the csv.&lt;BR /&gt;What I did so far is the following :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index =&amp;nbsp;myindex&amp;nbsp;[ |inputlookup mycsv.csv&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;| fields 10000 $uid ]&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="inherit"&gt;However this solution is not perfect.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="inherit"&gt;What&amp;nbsp;&lt;/FONT&gt;I&lt;FONT face="inherit"&gt;&amp;nbsp;&lt;/FONT&gt;would&lt;FONT face="inherit"&gt;&amp;nbsp;wanted to achieve should be like this&lt;BR /&gt;index=&amp;nbsp;&lt;/FONT&gt;myindex uid=2342334 or uid =34234234 or uid=(..)&lt;BR /&gt;&lt;BR /&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 10:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545551#M154554</guid>
      <dc:creator>Aaron283</dc:creator>
      <dc:date>2021-03-26T10:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545559#M154556</link>
      <description>&lt;P&gt;Hi Aaron&lt;/P&gt;&lt;P&gt;you can use directly the lookup comand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SCS/current/SearchReference/LookupCommandExamples" target="_blank"&gt;https://docs.splunk.com/Documentation/SCS/current/SearchReference/LookupCommandExamples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;inputlookup works different, you can search inside on your lookup table, with the lookup comand you can enrich your data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545559#M154556</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-03-26T11:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545562#M154559</link>
      <description>&lt;P&gt;thanks for the fast reply. Could you give me a short example?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545562#M154559</guid>
      <dc:creator>Aaron283</dc:creator>
      <dc:date>2021-03-26T11:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545564#M154561</link>
      <description>&lt;P&gt;sure&lt;/P&gt;&lt;P&gt;Basically you must have one field on your data present on the lookup table&lt;/P&gt;&lt;P&gt;by hypothesis will be "ID" field.&lt;/P&gt;&lt;P&gt;example&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = myindex | lookup&amp;nbsp; mycsvfile ID&amp;nbsp;OUTPUT UID ROLE |&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;with the association the field you can find the fields present on the lookup table to enrich your data set.&lt;/P&gt;&lt;P&gt;would be nice if you can confirm the solution&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545564#M154561</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-03-26T12:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545567#M154563</link>
      <description>&lt;P&gt;Sorry for the trouble, but I am still not sure if I understand it right.&lt;BR /&gt;so by doing "&lt;SPAN&gt;index = myindex | lookup mycsv.csv UID&amp;nbsp;OUTPUT UID | " all UIDs that are in mycsv.csv will be returned?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545567#M154563</guid>
      <dc:creator>Aaron283</dc:creator>
      <dc:date>2021-03-26T11:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545568#M154564</link>
      <description>&lt;P&gt;Exactly&lt;/P&gt;&lt;P&gt;with this search you can find your UID values on your dataset.&lt;/P&gt;&lt;P&gt;I really appreciate if you can confirm the solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 11:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545568#M154564</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-03-26T11:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545573#M154567</link>
      <description>&lt;P&gt;Will do so &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;However it seems not to work for me, or I am still not fully understanding it.&lt;BR /&gt;The UID is not part of index. the value I want to match the UID COLUMN from the CSV is in a JSON sth like this. things.attributes.UIDThingNumber&lt;BR /&gt;&lt;BR /&gt;So I want to do something like this:&lt;BR /&gt;index = myindex "things.attributes.UIDThingNumber"=123 or 456 or 789 and that does not seem to work the way you described it .&lt;BR /&gt;&lt;BR /&gt;I am really sorry if I haven't explained it right&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545573#M154567</guid>
      <dc:creator>Aaron283</dc:creator>
      <dc:date>2021-03-26T12:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545574#M154568</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232925"&gt;@Aaron283&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you have on your lookup table these fields&lt;/P&gt;&lt;P&gt;ROLE UID and ID&lt;/P&gt;&lt;P&gt;on your dataset you need ID field to match the data no UID field&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index = myindex | lookup mycsv.csv ID&amp;nbsp;OUTPUT UID&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you don't have any ID field&amp;nbsp; on your dataset you can create you ID field with eval comand&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Eval" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Eval&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:12:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545574#M154568</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-03-26T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search for IDS with inputlookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545575#M154569</link>
      <description>&lt;P&gt;I think I have much to learn. Still not getting it but thanks for the help&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 12:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-for-IDS-with-inputlookup/m-p/545575#M154569</guid>
      <dc:creator>Aaron283</dc:creator>
      <dc:date>2021-03-26T12:16:14Z</dc:date>
    </item>
  </channel>
</rss>

