<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputlookup returning 0 fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282878#M190589</link>
    <description>&lt;P&gt;Try this search. What do you get?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;UPDATED based on comments&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main sourcetype=web* dest_port=20 | lookup known_tcp_ports.csv dest_port AS dest_port OUTPUT application AS application
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 27 Jul 2016 20:07:07 GMT</pubDate>
    <dc:creator>sundareshr</dc:creator>
    <dc:date>2016-07-27T20:07:07Z</dc:date>
    <item>
      <title>inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282877#M190588</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I've done this a million times, but for some reason, it's not working for me today, and I suspect it's something really silly that just needs some fresh eyes on it.&lt;/P&gt;

&lt;P&gt;I have a .csv file:&lt;/P&gt;

&lt;P&gt;dest_port,application&lt;BR /&gt;
1,TCP Port Service Multiplexer (TCPMUX)&lt;BR /&gt;
5,Remote Job Entry (RJE)&lt;BR /&gt;
7,ECHO&lt;BR /&gt;
18,Message Send Protocol (MSP)&lt;BR /&gt;
20,FTP -- Data&lt;BR /&gt;
21,FTP -- Control&lt;BR /&gt;
...etc...&lt;/P&gt;

&lt;P&gt;I've created a lookup table file and lookup definition in the same app context. I run   &lt;CODE&gt;| inputlookup known_tcp_ports.csv&lt;/CODE&gt; and I get the table (with the order backwards, application first followed by dest_port).&lt;/P&gt;

&lt;P&gt;I created an automatic lookup that has input: dest_port = dest_port (exists in my data and identical name as port header in csv) and the output is application=application. This doesn't work, so I dug into it and even the normal lookup doesn't work!&lt;/P&gt;

&lt;P&gt;I'm staring at an event with dest_port=20 right now and when I run   &lt;CODE&gt;index=main sourcetype=web* dest_port=20 [ | inputlookup known_tcp_ports.csv ]&lt;/CODE&gt; I get bupkis.&lt;/P&gt;

&lt;P&gt;Any ideas? I'm sure it's something really simple.&lt;/P&gt;

&lt;P&gt;Edit: Running  &lt;CODE&gt;index=main dest_ip=* | lookup known_tcp_ports.csv dest_port OUTPUT application&lt;/CODE&gt; gets the application field. Not sure why I have to force it like that.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282877#M190588</guid>
      <dc:creator>j4adam</dc:creator>
      <dc:date>2020-09-29T10:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282878#M190589</link>
      <description>&lt;P&gt;Try this search. What do you get?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;UPDATED based on comments&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main sourcetype=web* dest_port=20 | lookup known_tcp_ports.csv dest_port AS dest_port OUTPUT application AS application
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282878#M190589</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-07-27T20:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282879#M190590</link>
      <description>&lt;P&gt;I get 285 events but no application field.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282879#M190590</guid>
      <dc:creator>j4adam</dc:creator>
      <dc:date>2016-07-27T20:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282880#M190591</link>
      <description>&lt;P&gt;The subsearch method ( &lt;CODE&gt;index=main sourcetype=web* dest_port=20 [ | inputlookup known_tcp_ports.csv ]&lt;/CODE&gt; ) is for filtering, not for data enrichment, so there won't be application column there. If the regular lookup work, check the syntax for the automatic lookup is correct and you're running the search is smart/verbose mode.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282880#M190591</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-07-27T20:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282881#M190592</link>
      <description>&lt;P&gt;If you want the applications field, you will have to use &lt;CODE&gt;lookup&lt;/CODE&gt; command. Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main sourcetype=web* dest_port=20 | lookup known_tcp_ports.csv dest_port AS dest_port OUTPUT application AS application 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282881#M190592</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2016-07-27T20:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282882#M190593</link>
      <description>&lt;P&gt;Can you edit your main post to include this so I can accept it and hopefully save future people the headache I went through? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:20:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282882#M190593</guid>
      <dc:creator>j4adam</dc:creator>
      <dc:date>2016-07-27T20:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup returning 0 fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282883#M190594</link>
      <description>&lt;P&gt;And there it is. It's for filtering. Sigh. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 20:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-returning-0-fields/m-p/282883#M190594</guid>
      <dc:creator>j4adam</dc:creator>
      <dc:date>2016-07-27T20:20:32Z</dc:date>
    </item>
  </channel>
</rss>

