Getting Data In

Using a CSV to search

ryangibson99
Explorer

I am pretty sure this involves lookups but here is what I am attempting.

I have a list of users in a CSV (users.csv) but it's about 70 names. I want to search a certain sourcetype for these names without having to finger bang them in one at a time. How do I do this? I feel like this is covered somewhere and I have RTFM already. Any assistance with an answer or at least a nudge in the right direction would be greatly appreciated!

Tags (2)

ryangibson99
Explorer

AWESOME! Thanks so much!

0 Karma

Brian_Osburn
Builder

you actually can do that quite easily (I had the same issue):

sourcetype=*yoursourcetype* [ | inputlookup users.csv | fields user]

This will expand to something like this:

sourcetype=*yoursourcetype* user=user1
sourcetype=*yoursourcetype* user=user2

Hope this helps!

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...