<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why isn't my lookup command working? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313532#M93865</link>
    <description>&lt;P&gt;My lookup file&lt;BR /&gt;
IOSVersion,Vulnerability,Risk,Refrence&lt;BR /&gt;
12.2(55)SE10,Cisco IOS and IOS XE Software DHCP Remote Code,Critical,&lt;BR /&gt;
12.2(55)SE10,Cisco IOS Software for Cisco Industrial Ethernet Switches,High,&lt;BR /&gt;
12.2(55)SE10,Multiple Cisco Products  Manipulation Vulnerability,Medium,&lt;BR /&gt;
12.2(55)SE10,SNMP Remote Code Execution Vulnerabilities in Ci,High,&lt;/P&gt;

&lt;P&gt;My Csv file &lt;BR /&gt;
Hostname,IOSVersion,IPAddress,index,source,sourcetype,splunk_server&lt;BR /&gt;
Gaandi(2nd-Floor),12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;BR /&gt;
Gaandi(3rd-Floor),12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;BR /&gt;
Dispatching,12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;/P&gt;</description>
    <pubDate>Tue, 28 Nov 2017 12:39:53 GMT</pubDate>
    <dc:creator>khanlarloo</dc:creator>
    <dc:date>2017-11-28T12:39:53Z</dc:date>
    <item>
      <title>Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313517#M93850</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a problem when searching my lookup field. I added a lookup file to my search with 3 fields (Vulnerability, Risk, Reference). But when I'm searching with stats command or something else it shows me a different result.&lt;/P&gt;

&lt;P&gt;Are there any solutions?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 07:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313517#M93850</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T07:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313518#M93851</link>
      <description>&lt;P&gt;Hi @ khanlarloo,&lt;/P&gt;

&lt;P&gt;Can you please provide your splunk query if possible?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:30:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313518#M93851</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T08:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313519#M93852</link>
      <description>&lt;P&gt;Hi  khanlarloo,&lt;BR /&gt;
could you share your search?&lt;BR /&gt;
Anyway check the file names and put a special attention to the cases of your values that could not match and if there are duplicate values!&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313519#M93852</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-28T08:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313520#M93853</link>
      <description>&lt;P&gt;Do have bit more detail about how you are calling the lookup and what your report looks like? i.e is this an automatic lookup or are you calling in within the report &lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313520#M93853</guid>
      <dc:creator>paulbannister</dc:creator>
      <dc:date>2017-11-28T08:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313521#M93854</link>
      <description>&lt;P&gt;sourcetype=csv |  stats count by Vulnerability &lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313521#M93854</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T08:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313522#M93855</link>
      <description>&lt;P&gt;it is automatic lookup.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313522#M93855</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T08:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313523#M93856</link>
      <description>&lt;P&gt;i add a csv file named net.csv my lookup csv file is ios.csv&lt;BR /&gt;
no there are no duplivate value&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313523#M93856</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T08:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313524#M93857</link>
      <description>&lt;P&gt;which fields have you mapped with automatic lookup ? When you try to search &lt;CODE&gt;sourcetype=csv&lt;/CODE&gt; without &lt;CODE&gt;stats&lt;/CODE&gt; command, are you able to see Vulnerability ,Risk,Refrence fields on left hand side as &lt;CODE&gt;Interesting Fields&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313524#M93857</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T08:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313525#M93858</link>
      <description>&lt;P&gt;yes.i can see them in right pannel.but when i search them it shows different result.not showing the exact number&lt;BR /&gt;
sourcetype=csv |  stats count by Vulnerability Risk Refrence &lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313525#M93858</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T08:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313526#M93859</link>
      <description>&lt;P&gt;Can you please explain "not showing exact number" ? what value are you expecting and what values you are getting?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:02:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313526#M93859</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T09:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313527#M93860</link>
      <description>&lt;P&gt;when i search in my csv file for exam i want to know the number of my vulnerability the number is 10 but when i do this in splunk it shows me more than 10&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:19:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313527#M93860</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T09:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313528#M93861</link>
      <description>&lt;P&gt;In which csv you have only 10 vulnerability, "net.csv" (means source file)? If yes then can you please try to search using &lt;CODE&gt;sourcetype=csv source=*net.csv* | stats count by Vulnerability&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:24:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313528#M93861</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T09:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313529#M93862</link>
      <description>&lt;P&gt;no vulnerability is in lookup file. &lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313529#M93862</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T09:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313530#M93863</link>
      <description>&lt;P&gt;So I have confusion here about file which you are talking about, can you please provide some sample data from source and lookup file which you are trying for automatic lookup (Please mask sensitive data or alter the data).&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313530#M93863</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T09:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313531#M93864</link>
      <description>&lt;P&gt;do i need subsearch ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 12:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313531#M93864</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T12:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313532#M93865</link>
      <description>&lt;P&gt;My lookup file&lt;BR /&gt;
IOSVersion,Vulnerability,Risk,Refrence&lt;BR /&gt;
12.2(55)SE10,Cisco IOS and IOS XE Software DHCP Remote Code,Critical,&lt;BR /&gt;
12.2(55)SE10,Cisco IOS Software for Cisco Industrial Ethernet Switches,High,&lt;BR /&gt;
12.2(55)SE10,Multiple Cisco Products  Manipulation Vulnerability,Medium,&lt;BR /&gt;
12.2(55)SE10,SNMP Remote Code Execution Vulnerabilities in Ci,High,&lt;/P&gt;

&lt;P&gt;My Csv file &lt;BR /&gt;
Hostname,IOSVersion,IPAddress,index,source,sourcetype,splunk_server&lt;BR /&gt;
Gaandi(2nd-Floor),12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;BR /&gt;
Gaandi(3rd-Floor),12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;BR /&gt;
Dispatching,12.2(55)SE10,,main,Network Switch.csv,csv,LAPTOP-IRG241OV&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 12:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313532#M93865</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T12:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313533#M93866</link>
      <description>&lt;P&gt;I don't know if I'm understanding the issue at hand correctly, but when you're using stats with several clauses (vulnerability, risk and refrence), it doesn't show the total count of each clause, but the count of all combinations of the values of the clauses.&lt;/P&gt;

&lt;P&gt;If you try to only count by one clause, e.g. vulnerability, do you get the number you are expecting then?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 13:02:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313533#M93866</guid>
      <dc:creator>hettervik</dc:creator>
      <dc:date>2017-11-28T13:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313534#M93867</link>
      <description>&lt;P&gt;no i don't get good result&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 13:14:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313534#M93867</guid>
      <dc:creator>khanlarloo</dc:creator>
      <dc:date>2017-11-28T13:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313535#M93868</link>
      <description>&lt;P&gt;Hi khanlarloo, &lt;/P&gt;

&lt;P&gt;First please clear if you are using automatic lookup or not?&lt;/P&gt;

&lt;P&gt;In case of automatic lookup, run a basic query and check if you are getting the field (Vulnerability ,Risk,Reference) in fields side bar or not. If yes, then check the fields name properly because fields name are case-sensitive.&lt;BR /&gt;
If the fields are not visible in fields sidebar then, there is issue with automatic look. Please check the lookup setting that will solve your issue.&lt;/P&gt;

&lt;P&gt;If you haven't used automatic lookup then you need to declare lookup command in the search like &lt;BR /&gt;
sourcetype=csv | lookup ios.csv output Vulnerability, Risk, reference | stats count by Vulnerability&lt;/P&gt;

&lt;P&gt;Make sure the fields name above should match exactly with the field name in csv file, even they are case sensitive.&lt;/P&gt;

&lt;P&gt;In case of any issue, reply back.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 13:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313535#M93868</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2017-11-28T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why isn't my lookup command working?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313536#M93869</link>
      <description>&lt;P&gt;ok, so I have replicated your sample data in my lab environment and I am assuming you are mapping source data and lookup data with &lt;CODE&gt;IOSVersion&lt;/CODE&gt;field so in this case when you try to run search &lt;CODE&gt;sourcetype=csv | stats count by Vulnerability&lt;/CODE&gt; it is giving count 3 for each Vulnerability which is correct because each Vulnerability is matching with IOSVersion in all 3 rows in source data so that's why it is giving count 3 for all 4 Vulnerability.&lt;/P&gt;

&lt;P&gt;Please correct me if I misunderstood your question/comment.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 13:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-isn-t-my-lookup-command-working/m-p/313536#M93869</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-28T13:26:57Z</dc:date>
    </item>
  </channel>
</rss>

