Getting Data In

Splunk lookups

ratra_007
New Member

Hi

I am having a really hard time in understanding the Splunk lookups process from your splunk documentation. I have configured the splunk lookups from an example csv file as per the steps given in the documentation. But not able to search or understand some aspects of it.

I would really appreciate if you could help me in this matter and get these doubts clear so I can be able to search my data from the lookups I have configured,.

Many Thanks!

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ratra_007,

I don't know which documentation you read, anyway here you can find useful documentation at https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Aboutlookupsandfieldactions and see a useful video at https://www.splunk.com/view/SP-CAAAE3F

Antway, in few words:

to enable lookups you have two ways:

then you need to create Lookup Definition [Settings -- Lookups -- Lookup Definitions -- New Lookup Definitions]; remember this otherwise your lookup isn't usable!

At this point you can use lookups in two ways:

in searches using the "| inputlookup" command  (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Inputlookup)

or to enrich your search with static data, using the "lookup" command (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Lookup)

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Could you be more specific, please?  What documentation are you following?  What exactly is not clear?  What is the search you are trying?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...