Getting Data In

Splunk lookups

ratra_007
New Member

Hi

I am having a really hard time in understanding the Splunk lookups process from your splunk documentation. I have configured the splunk lookups from an example csv file as per the steps given in the documentation. But not able to search or understand some aspects of it.

I would really appreciate if you could help me in this matter and get these doubts clear so I can be able to search my data from the lookups I have configured,.

Many Thanks!

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ratra_007,

I don't know which documentation you read, anyway here you can find useful documentation at https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Aboutlookupsandfieldactions and see a useful video at https://www.splunk.com/view/SP-CAAAE3F

Antway, in few words:

to enable lookups you have two ways:

then you need to create Lookup Definition [Settings -- Lookups -- Lookup Definitions -- New Lookup Definitions]; remember this otherwise your lookup isn't usable!

At this point you can use lookups in two ways:

in searches using the "| inputlookup" command  (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Inputlookup)

or to enrich your search with static data, using the "lookup" command (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Lookup)

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Could you be more specific, please?  What documentation are you following?  What exactly is not clear?  What is the search you are trying?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...