Getting Data In

Splunk search using CSV file data as input

psalibindla9524
New Member

I would like to search

index=main type=router OR type=switch OR type=firewall OR type=sysproxy ..

Instead i wanna do as below
test.csv
devicetype
router
switch
firewall
sysproxy
webproxy


index=main |search [|inputlookup test.csv |feilds devicetype]

It does not return the output. Can you please help how to get the results.

Tags (1)
0 Karma
1 Solution

sundareshr
Legend

In you first search example, the field name appears to be type whereas in the .csv field, field name is devicetype For your subsearch to work, the two needs to be the same. So you could either rename the field in the .csv by editing it, or you could try your search like this

index=main |search [|inputlookup test.csv |rename devicetype AS type | fields type]

View solution in original post

sundareshr
Legend

In you first search example, the field name appears to be type whereas in the .csv field, field name is devicetype For your subsearch to work, the two needs to be the same. So you could either rename the field in the .csv by editing it, or you could try your search like this

index=main |search [|inputlookup test.csv |rename devicetype AS type | fields type]

echalex
Builder

Since sundareshr was first to answer (in a comment), I'm demoting my answer to a comment. The solution is indeed correct, but you can shorten it a bit:

index=main [|inputlookup test.csv |rename devicetype AS type | fields type]

(oh, and I had a typo in my answer... Fixed now.)

0 Karma

tjrhodeback
New Member

There is also a typo "|feilds devicetype]"

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...