All Apps and Add-ons

How to read data from lookup file?

sbimizry
Engager

Hi, how to read data from the lookup file (.csv) using command lookup?
Lookup example:
FIELDS
field1
field2
field3
I try it: lookup file.csv FIELDS OUTPUT FIELDS AS newfield | table newfield but this not work, how I must write this search?
Thanks

0 Karma
1 Solution

woodcock
Esteemed Legend

The lookup command does not read data from a file, it correlates data. You have to have a field in your event whose values match the values of a field inside the lookup file. To truly read data from a lookup file, you use inputlookup like this:

| inputlookup <Your Lookup File Here>

View solution in original post

woodcock
Esteemed Legend

The lookup command does not read data from a file, it correlates data. You have to have a field in your event whose values match the values of a field inside the lookup file. To truly read data from a lookup file, you use inputlookup like this:

| inputlookup <Your Lookup File Here>
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...