Getting Data In

CSV lookup and count the value

Stephan
Engager

Hello,
I have a CSV file with two fields (ID and description) and I want to know if any of the IDs are found in a search. It would be great if the output comes in a table with count and the description.

CSV is like:
ID, description
1, abc
2, lmn
3, yxz

output:

IDdescriptioncount
2lmn6
1abc3

 

is that possible?

regards
Stephan

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

First you could count by id, then lookup the description from the csv file.

| stats count by id
| lookup file.csv

Depending on your actual search, you may need to adjust the field names to match 

View solution in original post

0 Karma

Stephan
Engager

Thanks a lot. That works. I have to add a "where isnotnull(description" to the command to filter the Events that are not in the CSV.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

First you could count by id, then lookup the description from the csv file.

| stats count by id
| lookup file.csv

Depending on your actual search, you may need to adjust the field names to match 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...