Getting Data In

CSV lookup and count the value

Stephan
Engager

Hello,
I have a CSV file with two fields (ID and description) and I want to know if any of the IDs are found in a search. It would be great if the output comes in a table with count and the description.

CSV is like:
ID, description
1, abc
2, lmn
3, yxz

output:

IDdescriptioncount
2lmn6
1abc3

 

is that possible?

regards
Stephan

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

First you could count by id, then lookup the description from the csv file.

| stats count by id
| lookup file.csv

Depending on your actual search, you may need to adjust the field names to match 

View solution in original post

0 Karma

Stephan
Engager

Thanks a lot. That works. I have to add a "where isnotnull(description" to the command to filter the Events that are not in the CSV.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

First you could count by id, then lookup the description from the csv file.

| stats count by id
| lookup file.csv

Depending on your actual search, you may need to adjust the field names to match 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...