Getting Data In

Importing Values for a Search from a CSV File

anording
Engager

Hello,

I´m new to splunk and need a short hint, concerning the following question:

I have some Firewall logs in Splunk and would like to search in the Destination (DST) field for specific Servers.

I uploaded a Server-2.csv and a " | inputlookup Server-2.csv  " shows the content of the file correctly.

A manual search like " index=firewall DST=8.8.8.8 " works fine.

From my point of view a " index=firewall [ | inputlookup Server-2.csv | table DST ] " should do a search for every entry in the CSV file, but I get no error and no result.
There should be a result because 8.8.8.8 is in the CSV as first entry.
Is the table entry the wrong syntax?

Sorry if this question is too simple, but I really would appreciate some hints.

Thx

André  
 

Labels (1)
0 Karma

anording
Engager

Dear thambisetty,

thx for the ultrafast reply. 😄

 

When i try your example, i will get the following error:
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.

The field DST is available in firewall raw events.

In the CSV File are only plain IP adresses nothing else.

Do i have to define a new field called "newfieldfromcsv", and if yes how?

I know newbie questions.  😆

THX again for your help!

André

0 Karma

thambisetty
SplunkTrust
SplunkTrust

[ | inputlookup Server-2.csv | table DST ]  is called sub search in Splunk. It has got limitations in the way you are using it.

can you try using lookup command like below:

assuming field DST is available in firewall raw events as well.

newfieldfromcsv is extra field from lookup and this will be used to get events matched with firewall events 

index=firewall | stats count by DST
| lookup Server-2.csv DST OUTPUT newfieldfromcsv
| where isnotnull(newfieldfromcsv)

 

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...