Getting Data In

Using a CSV to search

ryangibson99
Explorer

I am pretty sure this involves lookups but here is what I am attempting.

I have a list of users in a CSV (users.csv) but it's about 70 names. I want to search a certain sourcetype for these names without having to finger bang them in one at a time. How do I do this? I feel like this is covered somewhere and I have RTFM already. Any assistance with an answer or at least a nudge in the right direction would be greatly appreciated!

Tags (2)

ryangibson99
Explorer

AWESOME! Thanks so much!

0 Karma

Brian_Osburn
Builder

you actually can do that quite easily (I had the same issue):

sourcetype=*yoursourcetype* [ | inputlookup users.csv | fields user]

This will expand to something like this:

sourcetype=*yoursourcetype* user=user1
sourcetype=*yoursourcetype* user=user2

Hope this helps!

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...