Archive
Highlighted

Splunk DB Connect: Why am I unable to perform a lookup to enhance my dbquery results?

Builder

I'd like to be able to enhance DB Connect results with details in a lookup table file.

For some reason, the lookup is not working. I know the host field exists both in my dbquery results and my lookup table file. Here is the syntax I am using:

| dbquery "myconnection" "mysqlquery" 
| fields host interestingvalue 
| lookup hostdetails.csv host OUTPUT interestinghostdetail

Anyone have any ideas why this isn't working / wouldn't work?

Inputs appreciated!

0 Karma
Highlighted

Re: Splunk DB Connect: Why am I unable to perform a lookup to enhance my dbquery results?

SplunkTrust
SplunkTrust

I would do it differently and using subsearches and inputlookup:

| inputlookup hostdetails
| search [| dbquery "myconnection" "mysqlquery" | table host interestingvalue]
Highlighted

Re: Splunk DB Connect: Why am I unable to perform a lookup to enhance my dbquery results?

SplunkTrust
SplunkTrust

Keep in mind you could have the dbquery first and then filter based on your inputlookup

0 Karma
Highlighted

Re: Splunk DB Connect: Why am I unable to perform a lookup to enhance my dbquery results?

Esteemed Legend

Try without fields.

0 Karma
Highlighted

Re: Splunk DB Connect: Why am I unable to perform a lookup to enhance my dbquery results?

SplunkTrust
SplunkTrust

Make sure that the lookup of hostdetails.csv is available inside the DBXv1 app context.

0 Karma