upload your csv as a lookup table. Once you create a definition for your lookup, you can achieve with the below search
sourcetype="AAA" | lookup your_csv_definition_name userid output username | table _time userid username
Thanks for quick answer. I am still struggling how to upload the csv file from my computer to splunk, to make it available to the lookups. Do I need to save it to some certain folder, anything like "import" I need to do?
Something like this should get you started.
sourcetype="AAA" | lookup file.csv userid OUTPUT username | table _time userid username
If you create an automatic lookup you can omit the
lookup command from the search.