Getting Data In

Splunk search using CSV file data as input

psalibindla9524
New Member

I would like to search

index=main type=router OR type=switch OR type=firewall OR type=sysproxy ..

Instead i wanna do as below
test.csv
devicetype
router
switch
firewall
sysproxy
webproxy


index=main |search [|inputlookup test.csv |feilds devicetype]

It does not return the output. Can you please help how to get the results.

Tags (1)
0 Karma
1 Solution

sundareshr
Legend

In you first search example, the field name appears to be type whereas in the .csv field, field name is devicetype For your subsearch to work, the two needs to be the same. So you could either rename the field in the .csv by editing it, or you could try your search like this

index=main |search [|inputlookup test.csv |rename devicetype AS type | fields type]

View solution in original post

sundareshr
Legend

In you first search example, the field name appears to be type whereas in the .csv field, field name is devicetype For your subsearch to work, the two needs to be the same. So you could either rename the field in the .csv by editing it, or you could try your search like this

index=main |search [|inputlookup test.csv |rename devicetype AS type | fields type]

echalex
Builder

Since sundareshr was first to answer (in a comment), I'm demoting my answer to a comment. The solution is indeed correct, but you can shorten it a bit:

index=main [|inputlookup test.csv |rename devicetype AS type | fields type]

(oh, and I had a typo in my answer... Fixed now.)

0 Karma

tjrhodeback
New Member

There is also a typo "|feilds devicetype]"

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...