Alerting

How to use wildcard in multi fields in lookup table?

Erfan
Explorer

Hi

I want to use a lookup table as a whitelist for an alert.

1. I created a whitelist.csv lookup table including src, dst, protocol, user, whitelisted

src  |  dst  | protocol  | user | whitelisted

192.168.10.1 | 120.18.97.6 | * | * | true

192.168.10.5 | * | * | * | true

* | * | https | bob | true

2. I created a lookup definition with match type:  WILDCARD(src), WILDCARD(dst), WILDCARD(user), WILDCARD(protocol)

3. Added following line to my search:

| lookup whitelist.csv src user dst protocol

| where isnull(whitelisted)

 

But is does not work. Do I need to change anything?

Labels (2)
Tags (2)
0 Karma

manjunathmeti
Champion

hi @Erfan,

This is working for me, make sure your file contains data in the below format. There should not be any space b/w fields and values.

src,dst,protocol,user,whitelisted
192.168.10.1,120.18.97.6,*,*,true
192.168.10.5,*,*,*,true
*,*,https,bob,true

  

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...