Getting Data In

How to show customized data in output?

avd
New Member

Hi, I've recently started using Splunk logs. I have a query to fetch client IDs who call my APIs. These client IDs are some UUIDs. I would rather like to see a customized name for these IDs. 

For example, I can save the mapping of the client ID and its easy-to-read client name in a CSV or somewhere and want my Splunk query to show the client name.

Is this possible? Could someone help how to do it?

Labels (1)
0 Karma

jeffland
SplunkTrust
SplunkTrust

There is more than one way to do it. Since you mentioned csv already, let's use that. I'm going to assume it has two columns, uuid and client_id.

You need your csv in Splunk for this of course - so either upload it or create it in Splunk if you haven't done so already. Next, I'd suggest you create a lookup definition for your csv file. Then, you'd use your lookup like this:

index=this <your search finding UUIDs>
| lookup your_lookup_definition uuid OUTPUT client_id
| table _time client_id src_ip method (or whatever other fields you want)

If this is something you always want for this type of data, you might want to consider an automatic lookup. That would make splunk implicitly run that | lookup command for all searches against e.g. this sourcetype, so you wouldn't need to have it in every SPL explicitly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...