<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lookup command not working while inputlookup working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579867#M202051</link>
    <description>&lt;P&gt;Hi ITWhisperer,&lt;/P&gt;&lt;P&gt;I tried with "host" too instead of "Environment". It didn't work either. Can you suggest why..?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jan 2022 12:21:18 GMT</pubDate>
    <dc:creator>Mrig342</dc:creator>
    <dc:date>2022-01-04T12:21:18Z</dc:date>
    <item>
      <title>lookup command not working while inputlookup working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579852#M202049</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a .csv file&amp;nbsp; named Master_List.csv added to splunk lookup. It has the values of the fields "Tech Stack", "Environment", "Region" and "host" and has about 350 values per field. After adding the lookup table, inputlookup command is working fine and is giving the output table.&lt;/P&gt;&lt;P&gt;But when I am using lookup command in the below query, I am not getting the fields in the output on the left-hand side even though all the required permissions have been provided:&lt;/P&gt;&lt;P&gt;index=tibco_main sourcetype="NON-DIGITAL_TIBCO_INFRA_FS"&amp;nbsp; | regex _raw!="^\d+(\.\d+){0,2}\w"&lt;BR /&gt;| regex _raw!="/apps/tibco/datastore"&lt;BR /&gt;| rex field=_raw "(?ms)\s(?&amp;lt;Disk_Usage&amp;gt;\d+)%"&lt;BR /&gt;| rex field=_raw "(?ms)\%\s(?&amp;lt;File_System&amp;gt;\/\w+)"&lt;BR /&gt;| rex field=_raw "(?P&amp;lt;Time&amp;gt;\w+\s\w+\s\s\d+\s\d+\:\d+\:\d+\s\w+\s\d+)\s\d"&lt;BR /&gt;| rex field=_raw "(?ms)\d\s(?&amp;lt;Total&amp;gt;\d+(\.\d+){0,2})\w\s\d" | rex field=_raw "(?ms)G\s(?&amp;lt;Used&amp;gt;\d+(\.\d+){0,2})\w\s\d"&lt;BR /&gt;| lookup Master_List.csv "Environment"&lt;/P&gt;&lt;P&gt;Can someone please guide me on how to get the lookup command working or help modify the command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you..&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 11:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579852#M202049</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2022-01-04T11:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: lookup command not working while inputlookup working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579858#M202050</link>
      <description>&lt;P&gt;You don't appear to have an Environment field extracted, should you be looking up by host instead?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 11:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579858#M202050</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-04T11:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: lookup command not working while inputlookup working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579867#M202051</link>
      <description>&lt;P&gt;Hi ITWhisperer,&lt;/P&gt;&lt;P&gt;I tried with "host" too instead of "Environment". It didn't work either. Can you suggest why..?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 12:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579867#M202051</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2022-01-04T12:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: lookup command not working while inputlookup working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579868#M202052</link>
      <description>&lt;P&gt;What values for host do you have in your events and what values do you have in you csv file? Perhaps there is a mismatch?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 12:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579868#M202052</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-04T12:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: lookup command not working while inputlookup working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579942#M202064</link>
      <description>&lt;P&gt;Hi ITWhisperer,&lt;/P&gt;&lt;P&gt;There is no mismatch between the hosts available in the events and the csv file. However, now I am able to see the fields coming up and the lookup command is working fine. Don't know how it worked now, but seems my requirement is fulfilled.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 04:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/lookup-command-not-working-while-inputlookup-working/m-p/579942#M202064</guid>
      <dc:creator>Mrig342</dc:creator>
      <dc:date>2022-01-05T04:09:19Z</dc:date>
    </item>
  </channel>
</rss>

