Getting Data In
Highlighted

How to add a column/field based on csv table

Explorer

I have a search like:
sourcetype="AAA"|table _time userid, and I have a table like userid, username,
how to make the result as .....|table _time userid username.

Tags (2)
0 Karma
Highlighted

Re: How to add a column/field based on csv table

Influencer

upload your csv as a lookup table. Once you create a definition for your lookup, you can achieve with the below search

sourcetype="AAA" | lookup your_csv_definition_name userid output username | table _time userid username

View solution in original post

0 Karma
Highlighted

Re: How to add a column/field based on csv table

Explorer

Thanks for quick answer. I am still struggling how to upload the csv file from my computer to splunk, to make it available to the lookups. Do I need to save it to some certain folder, anything like "import" I need to do?

0 Karma
Highlighted

Re: How to add a column/field based on csv table

Influencer

go to settings -> lookups >lookup table files -> new

0 Karma
Highlighted

Re: How to add a column/field based on csv table

SplunkTrust
SplunkTrust

Something like this should get you started.

sourcetype="AAA" | lookup file.csv userid OUTPUT username | table _time userid username

If you create an automatic lookup you can omit the lookup command from the search.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How to add a column/field based on csv table

Explorer

I was going to accept both answers, but the system only allows one. Thanks to both of you!

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.