- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I am trying to use an inputlookup to enrich my search results table with additional fields from my inputlookup csv.
The scenario is that I am using a search to look for hostnames from events to match my CSV Device Name field and add the model number from my CSV also. I plan to add several more fields from my CSV but model field values is a start. I have tried to run the inputlookup sub-search but struggling to associate fields that are named differently between my search results and my CSV column titles.
Many thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Based on what you described, what you need is the lookup command
<your search>
|lookup <lookupfile> "Device Name" as hostname OUTPUT <comma separated fields from lookup>
Lookup documentation here - https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Lookup
Hope this helps.
Cheers
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Based on what you described, what you need is the lookup command
<your search>
|lookup <lookupfile> "Device Name" as hostname OUTPUT <comma separated fields from lookup>
Lookup documentation here - https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Lookup
Hope this helps.
Cheers
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That did the trick. Not sure why I steered into looking at inputlookup. Would you have any examples on applying inputlookup ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are multiple scenarios you use inputlookup
For example:
1. | inputlookup <lookup file>
This just outputs the content of the lookup file
2. <your search> |inputlookup <lookup file> append=true
This appends the content of your lookup file to the end of your search results
You can view more examples here - https://docs.splunk.com/Documentation/Splunk/8.0.0/SearchReference/Inputlookup
Cheers
