Getting Data In

Help on inputlookup subsearch

jip31
Motivator

Hi

I cross the results of a subsearch with a main search like this

index=toto [inputlookup test.csv

|eval user=Domain."\\"Sam

|table user]

|table _time user

Imagine I need to add a new lookup in my search 

For example i would try to do something like this 

index=toto [inputlookup test.csv OR inputlookup test2.csv

|eval user=Domain."\\"Sam

|table user]

|table _time user

How to do this please?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

you have to set the OR condition before the subsearch, something like this:

index=toto ([ | inputlookup test.csv OR inputlookup test2.csv | eval user=Domain."\\"Sam | table user ] OR [ | inputlookup test2.csv | eval user=Domain."\\"Sam | table user ])
| table _time user

Ciao.

Giuseppe

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Try this by combining the two lookups using append for the second lookup

index=toto [ 
  | inputlookup test.csv 
  | inputlookup test2.csv append=t
  | eval user=Domain."\\".Sam
  | table user]
| table _time user

I believe there is a missing '.' in your eval statement setting up user  and 'Sam' is a field name?

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

you have to set the OR condition before the subsearch, something like this:

index=toto ([ | inputlookup test.csv OR inputlookup test2.csv | eval user=Domain."\\"Sam | table user ] OR [ | inputlookup test2.csv | eval user=Domain."\\"Sam | table user ])
| table _time user

Ciao.

Giuseppe

bowesmana
SplunkTrust
SplunkTrust

Just pointing out here that the statement

| inputlookup test.csv OR inputlookup test2.csv

is not valid Splunk - you cannot do two inputlookup commands like that.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...