Getting Data In

Use of multiple CSV files in one search with wildcard

sigmabetagamma
New Member

Hi,
I would like to do a search in Splunk and need several CSV files.
These are monthly scans that all have the same columns and therefore can be easily merged.
Is there a way to do a wildcard search, such as

| inputlookup *_SCAN.csv

?
Otherwise, every month I have to revise all searches when a new report has been uploaded.

Tags (2)
0 Karma

schose
Builder

You can use a lookup definition to point to the recent .csv file. This would help you not to revise the searches.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...