All Apps and Add-ons

How do I store a specific field in lookup?

smanojkumar
Communicator

Hi There!

    I need to add a specific field in the lookup and keeping the all old data as it is,

   I'm having lookup1_kvstore , which consists of several fields and check_date as well
   also lookup2.csv consists of check_date, src_name , I need to update check_date from lookup2.csv to lookup1_kvstore and keeping all the old fields as it is except check_date.

 

Thanks in Advance!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming src_name exists in both lookups, try something like this

| inputlookup lookup1_kvstore
| lookup lookup2.csv src_name OUTPUT check_date
| outputlookup lookup1_kvstore
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...