All Apps and Add-ons

How do I store a specific field in lookup?

smanojkumar
Contributor

Hi There!

    I need to add a specific field in the lookup and keeping the all old data as it is,

   I'm having lookup1_kvstore , which consists of several fields and check_date as well
   also lookup2.csv consists of check_date, src_name , I need to update check_date from lookup2.csv to lookup1_kvstore and keeping all the old fields as it is except check_date.

 

Thanks in Advance!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming src_name exists in both lookups, try something like this

| inputlookup lookup1_kvstore
| lookup lookup2.csv src_name OUTPUT check_date
| outputlookup lookup1_kvstore
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...