<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with lookup query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563060#M196173</link>
    <description>&lt;P&gt;You could try creating a shortened version of the source field which matches the format you have in your lookup file&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=int_gcg_apac_solace_166076 host="mwgcb-csrla0*U*" source="/logs/confluent/connect-distributed/apac/TW/*" "Task is being killed and will not recover until manually restarted" | rex field=_raw "(?ms)id\=(?P&amp;lt;Connector&amp;gt;(\w+\.){1,9}\w+\-\d)\}"
| rex field=source "^(?&amp;lt;src&amp;gt;(/[^/]+){5})"
| eval src=src."/*" 
| lookup region_lookup.csv src&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 12 Aug 2021 11:54:07 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-08-12T11:54:07Z</dc:date>
    <item>
      <title>Need help with lookup query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563057#M196171</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am using below query to search for certain logs:&lt;/P&gt;&lt;P&gt;index=int_gcg_apac_solace_166076 host="mwgcb-csrla0*U*" source="/logs/confluent/connect-distributed/apac/TW/*" "Task is being killed and will not recover until manually restarted" | rex field=_raw "(?ms)id\=(?P&amp;lt;Connector&amp;gt;(\w+\.){1,9}\w+\-\d)\}" | lookup region_lookup.csv "source"&lt;/P&gt;&lt;P&gt;But while using the command | lookup region_lookup.csv "source", its not getting me any result based on the lookup table for the Region.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a query using lookup table which will be as below:&lt;/P&gt;&lt;TABLE width="470"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="330"&gt;source&lt;/TD&gt;&lt;TD width="140"&gt;Region&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/HK/*&lt;/TD&gt;&lt;TD&gt;HongKong&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/SG/*&lt;/TD&gt;&lt;TD&gt;Singapore&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/AU/*&lt;/TD&gt;&lt;TD&gt;Australia&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/VN/*&lt;/TD&gt;&lt;TD&gt;Vietnam&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/MY/*&lt;/TD&gt;&lt;TD&gt;Malaysia&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/ID/*&lt;/TD&gt;&lt;TD&gt;Indonesia&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/TH/*&lt;/TD&gt;&lt;TD&gt;Thailand&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="330"&gt;/logs/confluent/connect-distributed/apac/TW/*&lt;/TD&gt;&lt;TD&gt;Taiwan&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Each source have multiple folders inside it e.g. "logs/confluent/connect-distributed/apac/TW/*" will have file paths like "logs/confluent/connect-distributed/apac/TW/kafkaconnect.log", "logs/confluent/connect-distributed/apac/TW/kafkaconnect.log1", "logs/confluent/connect-distributed/apac/TW/kafkaconnect.log2" and so on..&amp;nbsp; And the searched indicator&amp;nbsp;"Task is being killed and will not recover until manually restarted" may go into any of the folders.&lt;/P&gt;&lt;P&gt;Is there any way I can use, so that I can use the lookup table as desired..?&lt;BR /&gt;Your kind advise will be highly appreciated..&lt;/P&gt;&lt;P&gt;Thank You..!!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 11:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563057#M196171</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2021-08-12T11:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with lookup query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563060#M196173</link>
      <description>&lt;P&gt;You could try creating a shortened version of the source field which matches the format you have in your lookup file&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=int_gcg_apac_solace_166076 host="mwgcb-csrla0*U*" source="/logs/confluent/connect-distributed/apac/TW/*" "Task is being killed and will not recover until manually restarted" | rex field=_raw "(?ms)id\=(?P&amp;lt;Connector&amp;gt;(\w+\.){1,9}\w+\-\d)\}"
| rex field=source "^(?&amp;lt;src&amp;gt;(/[^/]+){5})"
| eval src=src."/*" 
| lookup region_lookup.csv src&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 12 Aug 2021 11:54:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563060#M196173</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-12T11:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with lookup query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563093#M196184</link>
      <description>&lt;P&gt;Thank you very much ITWhisperer..!!&amp;nbsp; You Rock..!!&lt;/P&gt;&lt;P&gt;The query worked perfect and I am able to get my desired output.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 15:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-with-lookup-query/m-p/563093#M196184</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2021-08-12T15:48:10Z</dc:date>
    </item>
  </channel>
</rss>

