<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I compare my lookup table to multiple fields? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258328#M77403</link>
    <description>&lt;P&gt;Many people do not know that with the &lt;CODE&gt;format&lt;/CODE&gt; command, you have complete control over how a subsearch builds a search.  Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic GROUPBY All_Traffic.src_ip
| search [inputlookup ipLookups.csv | fields +  ipAddress| rename ipAddress as All_Traffic.src_ip
          | eval All_Traffic.dst_ip=All_Traffic.src_ip| format "(" "" "OR" "" "OR" ")"]
| table All_Traffic.src_ip count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 24 Jan 2017 05:59:02 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-01-24T05:59:02Z</dc:date>
    <item>
      <title>How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258325#M77400</link>
      <description>&lt;P&gt;I have a lookup table with IP address indicators that I would like to be alerted on whether the IP address is the source or destination.  Is there a way to compare my indicators against both source and destination IP addresses so that a match on either one counts?&lt;/P&gt;

&lt;P&gt;If I had a single indicator, the search would look like &lt;CODE&gt;|tstats count FROM datamodel=Network_Traffic.All_Traffic where&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;All_Traffic.src_ip=8.8.8.8 or All_Traffic.dest_ip=8.8.8.8
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I have a lookup, I know how to search vs just source or destination, &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic
GROUPBY All_Traffic.src_ip | search [inputlookup ipLookups.csv | fields +
ipAddress| rename ipAddress as All_Traffic.src_ip] |table All_Traffic.src_ip count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But is there a way for my ipAddress values to be compared against both source and destination so that a match on either one counts?  As I think about it, I suppose that I could append an entire search but it feels like something that should be accomplishable in one pass&lt;/P&gt;

&lt;P&gt;append version, showing an overly complex search for something simple:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic
GROUPBY All_Traffic.src_ip | search [inputlookup ipLookups.csv 
| fields + ipAddress| rename ipAddress as All_Traffic.src_ip] 
| rename All_Traffic.src_ip as ip | table type ip count
|append [ tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic
GROUPBY All_Traffic.dest_ip | search [inputlookup ipLookups.csv 
| fields + ipAddress| rename ipAddress as All_Traffic.dest_ip] 
| rename All_Traffic.dest_ip as ip | table type ip count ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Jan 2017 23:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258325#M77400</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2017-01-23T23:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258326#M77401</link>
      <description>&lt;P&gt;Have you seen the lookup command?  You can use it multiple times...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; |lookup ipLookups.csv ipAddress AS All_Traffic.src_ip OUTPUT otherFieldInLookup
 |lookup ipLookups.csv ipAddress AS All_Traffic.dst_ip OUTPUT otherFieldInLookup
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Lookup"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Lookup&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;otherFieldInLookup in my example can be any number of other space separated field names from the lookup.  &lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258326#M77401</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-01-24T00:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258327#M77402</link>
      <description>&lt;P&gt;I don't have your data to test against, but something like this should work.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic
 GROUPBY All_Traffic.src_ip All_Traffic.dest_ip 
  | lookup iplookups.csv All_Traffic.src_ip as ipAddress OutputNew ipAddress as FoundSrc
  | lookup iplookups.csv All_Traffic.dest_ip as ipAddress OutputNew ipAddress as FoundDest
  | eval DropThis = IF(coalesce(FoundSrc,FoundDest)."" = "", 1,0)
  | search DropThis=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It's my guess that you'll want to see which IP tripped the flag, and whether it was a source or destination.  That query should give you that data in a brief format.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:13:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258327#M77402</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-24T00:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258328#M77403</link>
      <description>&lt;P&gt;Many people do not know that with the &lt;CODE&gt;format&lt;/CODE&gt; command, you have complete control over how a subsearch builds a search.  Try this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=t count FROM datamodel=Network_Traffic.All_Traffic GROUPBY All_Traffic.src_ip
| search [inputlookup ipLookups.csv | fields +  ipAddress| rename ipAddress as All_Traffic.src_ip
          | eval All_Traffic.dst_ip=All_Traffic.src_ip| format "(" "" "OR" "" "OR" ")"]
| table All_Traffic.src_ip count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2017 05:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258328#M77403</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-24T05:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258329#M77404</link>
      <description>&lt;P&gt;MonkeyK - If your question has been answered, please "accept" the best or most helpful answer.  Doesn't matter which one.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 23:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258329#M77404</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-25T23:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258330#M77405</link>
      <description>&lt;P&gt;thank you for explaining this approach.  I compared this to the append approach and was surprised to find &lt;BR /&gt;
Append: runtime=38s, size=0.17MB&lt;BR /&gt;
two lookups: runtime=2m, size=31.48MB&lt;/P&gt;

&lt;P&gt;I find the two lookup approach more readable, but I guess that I have to stick to the append approach for resource utilization.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 00:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258330#M77405</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2017-01-26T00:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258331#M77406</link>
      <description>&lt;P&gt;this is very interesting.  I was not able to get it to work, but I will study it further.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 00:01:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258331#M77406</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2017-01-26T00:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258332#M77407</link>
      <description>&lt;P&gt;Ah.  Your search times actually make perfect sense.  If you are only getting the summary values, and only using the All_Traffic.src_ip  OR the All_Traffic.dest_ip, then each pass at the indexes doesn't have to do any real work.  On the other hand,  grouping by BOTH those fields requires a crawl and some summarizing.&lt;/P&gt;

&lt;P&gt;Try this and see if it cuts your time any.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; tstats summariesonly=t count 
 FROM datamodel=Network_Traffic.All_Traffic
 GROUPBY All_Traffic.src_ip 
| rename All_Traffic.src_ip as ip 
| eval direction="source"
| fields type direction ip count
| append 
    [ tstats summariesonly=t count 
     FROM datamodel=Network_Traffic.All_Traffic
     GROUPBY All_Traffic.dest_ip 
    | rename All_Traffic.dest_ip as ip 
    | eval direction="dest"
    | fields type direction ip count
    ]
| search 
    [inputlookup ipLookups.csv 
    | fields + ipAddress
    | rename ipAddress as ip
    ] 
| table type direction ip count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258332#M77407</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-09-29T12:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I compare my lookup table to multiple fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258333#M77408</link>
      <description>&lt;P&gt;Thank you! this approach is much cleaner.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 23:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-compare-my-lookup-table-to-multiple-fields/m-p/258333#M77408</guid>
      <dc:creator>MonkeyK</dc:creator>
      <dc:date>2017-02-02T23:41:09Z</dc:date>
    </item>
  </channel>
</rss>

