Getting Data In

Help on inputlookup subsearch

jip31
Motivator

Hi

I cross the results of a subsearch with a main search like this

index=toto [inputlookup test.csv

|eval user=Domain."\\"Sam

|table user]

|table _time user

Imagine I need to add a new lookup in my search 

For example i would try to do something like this 

index=toto [inputlookup test.csv OR inputlookup test2.csv

|eval user=Domain."\\"Sam

|table user]

|table _time user

How to do this please?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

you have to set the OR condition before the subsearch, something like this:

index=toto ([ | inputlookup test.csv OR inputlookup test2.csv | eval user=Domain."\\"Sam | table user ] OR [ | inputlookup test2.csv | eval user=Domain."\\"Sam | table user ])
| table _time user

Ciao.

Giuseppe

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Try this by combining the two lookups using append for the second lookup

index=toto [ 
  | inputlookup test.csv 
  | inputlookup test2.csv append=t
  | eval user=Domain."\\".Sam
  | table user]
| table _time user

I believe there is a missing '.' in your eval statement setting up user  and 'Sam' is a field name?

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

you have to set the OR condition before the subsearch, something like this:

index=toto ([ | inputlookup test.csv OR inputlookup test2.csv | eval user=Domain."\\"Sam | table user ] OR [ | inputlookup test2.csv | eval user=Domain."\\"Sam | table user ])
| table _time user

Ciao.

Giuseppe

bowesmana
SplunkTrust
SplunkTrust

Just pointing out here that the statement

| inputlookup test.csv OR inputlookup test2.csv

is not valid Splunk - you cannot do two inputlookup commands like that.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...