Getting Data In

Using CSV file as input to search

insomniacnerd94
Explorer

I am trying to use a list from a CSV file to query results for that list, but I only get a result from the first row.

The data looks like such;
workstation_1
workstation_2
workstation_3

The query looks like such;
index="wineventlog" Source_Workstation=* [inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as search] | table Source_Workstation, _time, Logon_Account | dedup Source_Workstation

0 Karma
1 Solution

koshyk
Super Champion

Few mistakes in your search

  1. You need to put a | character before inputlookup

index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" ...

  1. What is the name of the field in WinEventLog where you want WorkStation Name to be compared with? I don't think "Source_Workstation" is the field name. Assuming hostname is the field you want to compare the search would look like..

example

index="wineventlog" [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | stats count by Source_Workstation, _time, Logon_Account

View solution in original post

koshyk
Super Champion

Few mistakes in your search

  1. You need to put a | character before inputlookup

index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" ...

  1. What is the name of the field in WinEventLog where you want WorkStation Name to be compared with? I don't think "Source_Workstation" is the field name. Assuming hostname is the field you want to compare the search would look like..

example

index="wineventlog" [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | stats count by Source_Workstation, _time, Logon_Account

insomniacnerd94
Explorer

Thanks for the help, but I actually figured it out. I had the following query;

index="wineventlog" Source_Workstation=* [|inputlookup test.csv | fields "Workstation Name" | rename "Workstation Name" as Source_Workstation] | table Source_Workstation, _time, Logon_Account | dedup Source_Workstation

0 Karma

woodcock
Esteemed Legend

Be sure to click Accept on this answer or post your own and accept that one. Do one or the other to close this question.

koshyk
Super Champion

great. So the above search which I provided above, should also return similar results and would be faster as it directly uses stats count

Please upvote/accept, if it helped you

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...