<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search with lookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569615#M198529</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Now, i have some changes but still i can't list with lookup file's value;&lt;/P&gt;&lt;P&gt;&amp;lt;base search&amp;gt; |eval user_info=host."".Huawei_int |lookup fttb_user.csv ipport as user_info OUTPUT user |search user_info=10.58.35.144GigabitEthernet0/0/7 | stats count by Date,user_info,Huawei_status | sort -count |where count&amp;gt;6&lt;/P&gt;&lt;P&gt;Stats without user field;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_0-1633384062035.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16269iF3B38D3C8104E208/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_0-1633384062035.png" alt="corehan_0-1633384062035.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stats with user field;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_1-1633384118621.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16270iEEB063200CD004D7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_1-1633384118621.png" alt="corehan_1-1633384118621.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;lookup csv file;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_2-1633384255583.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16271iCE168BA9749335D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_2-1633384255583.png" alt="corehan_2-1633384255583.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Oct 2021 21:51:14 GMT</pubDate>
    <dc:creator>corehan</dc:creator>
    <dc:date>2021-10-04T21:51:14Z</dc:date>
    <item>
      <title>search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569485#M198490</link>
      <description>&lt;P&gt;Hello dears,&lt;/P&gt;&lt;P&gt;I have switches, ip address,ports and i want list with users which are connected to the ports. Users informations include lookup file which name is list.csv, so;&lt;/P&gt;&lt;P&gt;list.csv contains : ip,port,user&lt;/P&gt;&lt;P&gt;&amp;lt;base_search&amp;gt;&amp;nbsp; | lookup list.csv ip as host &lt;FONT color="#FF0000"&gt;AND port as if_name&lt;/FONT&gt; OUTPUT user |stats count by host,if_name,user&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 19:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569485#M198490</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-10-03T19:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569488#M198492</link>
      <description>&lt;P&gt;What is your question?&lt;/P&gt;&lt;P&gt;BTW, the &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; command does not recognize &lt;FONT face="courier new,courier"&gt;AND&lt;/FONT&gt; as a keyword.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 00:25:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569488#M198492</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-04T00:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569495#M198496</link>
      <description>&lt;P&gt;Exactly, so highleted with red. if match host and if_name with lookup file, then list user info.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 05:04:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569495#M198496</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-10-04T05:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569539#M198514</link>
      <description>&lt;P&gt;Again I ask: What is your question?&lt;/P&gt;&lt;P&gt;So you know enough to highlight the syntax error in red, but not enough to look up the syntax and fix it?&lt;/P&gt;&lt;P&gt;Please describe the problem you are trying to solve.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 12:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569539#M198514</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-04T12:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569544#M198516</link>
      <description>&lt;P&gt;Sorry, i can't list with user info, i need lookup syntax which is check ip and port from lookup file. How can i do this with correct lookup syntax? I should check 2 multivalue field and than add to user info. I hope, understand.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;base_search&amp;gt;&amp;nbsp; | lookup list.csv ip as host&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;AND port as if_name&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;OUTPUT user |stats count by host,if_name,user&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 13:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569544#M198516</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-10-04T13:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569559#M198519</link>
      <description>&lt;P&gt;The syntax for the &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; command is in the Search Reference manual at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/SearchReference/Lookup#Syntax" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/SearchReference/Lookup#Syntax&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Did you try removing the &lt;FONT face="courier new,courier"&gt;AND&lt;/FONT&gt; keyword as I implied in my first reply?&lt;/P&gt;&lt;P&gt;I can't say I've tried it before, but I believe lookups do not work with multi-value fields.&amp;nbsp; You'll have to use &lt;FONT face="courier new,courier"&gt;mvindex&lt;/FONT&gt; or another multi-value function to get a single-value field for the lookup.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 13:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569559#M198519</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-04T13:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569615#M198529</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Now, i have some changes but still i can't list with lookup file's value;&lt;/P&gt;&lt;P&gt;&amp;lt;base search&amp;gt; |eval user_info=host."".Huawei_int |lookup fttb_user.csv ipport as user_info OUTPUT user |search user_info=10.58.35.144GigabitEthernet0/0/7 | stats count by Date,user_info,Huawei_status | sort -count |where count&amp;gt;6&lt;/P&gt;&lt;P&gt;Stats without user field;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_0-1633384062035.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16269iF3B38D3C8104E208/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_0-1633384062035.png" alt="corehan_0-1633384062035.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stats with user field;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_1-1633384118621.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16270iEEB063200CD004D7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_1-1633384118621.png" alt="corehan_1-1633384118621.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;lookup csv file;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="corehan_2-1633384255583.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16271iCE168BA9749335D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="corehan_2-1633384255583.png" alt="corehan_2-1633384255583.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 21:51:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569615#M198529</guid>
      <dc:creator>corehan</dc:creator>
      <dc:date>2021-10-04T21:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: search with lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569683#M198551</link>
      <description>&lt;P&gt;It's impossible to say why the data is not matching the lookup without seeing the data.&amp;nbsp; Please share some samples.&lt;/P&gt;&lt;P&gt;Also, the &lt;FONT face="courier new,courier"&gt;lookup&lt;/FONT&gt; command is specifying the 'user_info' field, which does not exist in the lookup file.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-with-lookup/m-p/569683#M198551</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-05T12:19:01Z</dc:date>
    </item>
  </channel>
</rss>

