Knowledge Management

How to get lookup header names as field's values

smart111
Explorer

smart111_0-1634832219579.png


Is there any way to get those header names as field values from lookup files?
Please give me any idea with SPL

 

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You could transpose, duplicate the header column and transpose again

| inputlookup lookup.csv
| transpose 0 header_field="NAME" column_name="NAME"
| eval header=NAME
| transpose 0 header_field=header column_name="NAME"

 

View solution in original post

ryanoconnor
Builder

Can you explain the use case a little bit more? This looks like it might be a screenshot from Microsoft Excel. 

Have you looked into the Lookup File Editor App?  https://splunkbase.splunk.com/app/1724/

0 Karma

smart111
Explorer

Thank you for answering @ryanoconnor 

I actually wanted to set a dropdown list of lookup header values on dashboard and make it possible to choose a primary key to  lookup reference field dynamically.

Thank you for your kindness.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could transpose, duplicate the header column and transpose again

| inputlookup lookup.csv
| transpose 0 header_field="NAME" column_name="NAME"
| eval header=NAME
| transpose 0 header_field=header column_name="NAME"

 

smart111
Explorer

Thank you so much, @ITWhisperer 

This way is exactly I wanted.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...