<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup Tables and Comments in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96196#M24847</link>
    <description>&lt;P&gt;have a look at my updated answer for an example of another way to do it&lt;/P&gt;</description>
    <pubDate>Fri, 21 Oct 2011 21:35:30 GMT</pubDate>
    <dc:creator>Drainy</dc:creator>
    <dc:date>2011-10-21T21:35:30Z</dc:date>
    <item>
      <title>Lookup Tables and Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96193#M24844</link>
      <description>&lt;P&gt;I currently am using a lookup table to match Host Names with a "grouping" category.  However, there are a ton of entries in there and the order I have them in the file isn't directly obvious, so to make it easier for me to search through and edit the file, I'd love it if I could add "comments" to the lookup file.  Is this possible?  Can we start lines with a ':' or a '#' character or something and cause that line to be ignored during the lookup process?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2011 18:36:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96193#M24844</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2011-10-21T18:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Tables and Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96194#M24845</link>
      <description>&lt;P&gt;Well its a CSV so you can't comment it.&lt;BR /&gt;
But, you could add a comment field and simply not reference it during the lookup process? That way it will idle there un-used&lt;/P&gt;

&lt;P&gt;UPDATE:&lt;/P&gt;

&lt;P&gt;One way could be,&lt;/P&gt;

&lt;P&gt;host,ip,comment&lt;BR /&gt;
BOB,127.0.0.1,danger danger!&lt;/P&gt;

&lt;P&gt;But you could avoid referencing the comment field completely&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2011 21:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96194#M24845</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2011-10-21T21:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Tables and Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96195#M24846</link>
      <description>&lt;P&gt;Yeah, I was just thinking that a "generic" Host Name like "#comment#" that would never actually be the name of a machine could just be treated as a comment.  I was hoping that maybe Splunk's lookup process would have its own construct built-in that ignored certain lines.  But you're probably right in that it most likely wouldn't.  ^_^&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2011 21:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96195#M24846</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2011-10-21T21:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup Tables and Comments</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96196#M24847</link>
      <description>&lt;P&gt;have a look at my updated answer for an example of another way to do it&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2011 21:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-Tables-and-Comments/m-p/96196#M24847</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2011-10-21T21:35:30Z</dc:date>
    </item>
  </channel>
</rss>

