Getting Data In

Input from csv from my local drive

wang
Path Finder

I have a list of IPs that I'd like to use as input to a saved search. Instead of manually typing (ip=x OR ip=y OR ip=z), if I have a csv file on my local drive with a single column of IPs, is there a way for the saved search to dynamically import the IPs?

I've look at inputcsv but that seems to expect the csv to reside on the server. I want to pull the csv from my local disk, or write a form that prompts for the location of the csv on my local disk.

Tags (1)
0 Karma

sinclairmachado
Explorer

Just an alternative, you can use lookup table.
Lookup table has back end as a csv file. You can update the csv (lookup table) from the query.

But I guess your request is to use the csv from local machine, it will be difficult;
1) It will require authentication
2) Data will not be consistent across users in the organization as they will not be able to get the results that you can see (if there are more than 1 users of splunk).

0 Karma

lraab
New Member

It isn't really practical to ssh the file up to the server.
1. It is too hard to remember the incantation, and would take too long. Not all of our Splunk users are that savvy.
2. Our Splunk users do not have SSH access to the production splunk server machine

Any chance of making this an enhancement request?

0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

As you've discovered, inputcsv is the correct answer here. If the csv file can only be generated on your local drive, you should write a script that takes the local file and uploads it to the proper location on the Splunk server.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...