All Apps and Add-ons

How to read data from lookup file?

sbimizry
Engager

Hi, how to read data from the lookup file (.csv) using command lookup?
Lookup example:
FIELDS
field1
field2
field3
I try it: lookup file.csv FIELDS OUTPUT FIELDS AS newfield | table newfield but this not work, how I must write this search?
Thanks

0 Karma
1 Solution

woodcock
Esteemed Legend

The lookup command does not read data from a file, it correlates data. You have to have a field in your event whose values match the values of a field inside the lookup file. To truly read data from a lookup file, you use inputlookup like this:

| inputlookup <Your Lookup File Here>

View solution in original post

woodcock
Esteemed Legend

The lookup command does not read data from a file, it correlates data. You have to have a field in your event whose values match the values of a field inside the lookup file. To truly read data from a lookup file, you use inputlookup like this:

| inputlookup <Your Lookup File Here>
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...