<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: commas in lookup tables in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38513#M8753</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've got another comma problem with a lookup. I would like to create a lookup for field values in the eventdata like &lt;STRONG&gt;Test,A&lt;/STRONG&gt;, which i want to replace with a new value.&lt;/P&gt;

&lt;P&gt;My lookuptable looks like this:&lt;/P&gt;

&lt;P&gt;"Test,A" - New Value&lt;/P&gt;

&lt;P&gt;I used the quotes to achieve, that the value is not splitted up in the lookup. But then I'm not able to use the lookup, because there is no match. The values in the eventdata don't have quotes...&lt;/P&gt;

&lt;P&gt;Any ideas how to achieve my goal?&lt;/P&gt;

&lt;P&gt;Thanks, Heinz&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2013 10:34:38 GMT</pubDate>
    <dc:creator>HeinzWaescher</dc:creator>
    <dc:date>2013-11-20T10:34:38Z</dc:date>
    <item>
      <title>commas in lookup tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38510#M8750</link>
      <description>&lt;P&gt;hi, I am using a look-up table, however some of the fields have commas in them. - as you would expect these do not match. Any idea how to get around this,&lt;/P&gt;

&lt;P&gt;I have tried adding a &lt;CODE&gt;\&lt;/CODE&gt; before the comma but this does not help&lt;BR /&gt;
I can not remove the comma as this will not match the data&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2012 11:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38510#M8750</guid>
      <dc:creator>stephen123</dc:creator>
      <dc:date>2012-11-19T11:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: commas in lookup tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38511#M8751</link>
      <description>&lt;P&gt;If you can edit the CSV that you are using as a lookup directely, have you tried including the offending field in quotations (e.g. &lt;CODE&gt;"&lt;/CODE&gt;). For example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;field0, field1, field2
efuieb, "foo,bar", blah
inevei, "foo", blah
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2012 12:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38511#M8751</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-11-19T12:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: commas in lookup tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38512#M8752</link>
      <description>&lt;P&gt;awesome - thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Nov 2012 12:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38512#M8752</guid>
      <dc:creator>stephen123</dc:creator>
      <dc:date>2012-11-19T12:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: commas in lookup tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38513#M8753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've got another comma problem with a lookup. I would like to create a lookup for field values in the eventdata like &lt;STRONG&gt;Test,A&lt;/STRONG&gt;, which i want to replace with a new value.&lt;/P&gt;

&lt;P&gt;My lookuptable looks like this:&lt;/P&gt;

&lt;P&gt;"Test,A" - New Value&lt;/P&gt;

&lt;P&gt;I used the quotes to achieve, that the value is not splitted up in the lookup. But then I'm not able to use the lookup, because there is no match. The values in the eventdata don't have quotes...&lt;/P&gt;

&lt;P&gt;Any ideas how to achieve my goal?&lt;/P&gt;

&lt;P&gt;Thanks, Heinz&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2013 10:34:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/commas-in-lookup-tables/m-p/38513#M8753</guid>
      <dc:creator>HeinzWaescher</dc:creator>
      <dc:date>2013-11-20T10:34:38Z</dc:date>
    </item>
  </channel>
</rss>

