Knowledge Management

using wild card in a lookup column?

pavanae
Builder

I have a lookup sample.csv as follows whereas one of the host value is empty 

 

Name Host
TEST_USERabc, def
USER_1*
user_3ghi

 

Now I use the lookup in a search. Now for the USER_1 Host I want to use the wild card. Using astrick symbol directly in the lookup doesn't working. Is there any way I can add a wild card for USER_1. 

A little research on the Splunk docs gives me some inputs like I need to use props and transforms to do so. I don't have a props or transforms exists for that application. Can I create a condition in props, transforms just for the above purpose. If so what should be the stanzas should be in both the configuration files. 

 

Any Help would be great. 

 

Labels (1)
0 Karma

somesoni2
Revered Legend

If you're trying to do wildcard match when you do a lookup (running "| lookup" command), then you can follow this to setup wildcard match:

https://community.splunk.com/t5/Splunk-Search/Can-we-use-wildcard-characters-in-a-lookup-table/m-p/9...

 

If not, then you should add more details like how you're using the lookup, what output you get now and what is want to see as the output.

0 Karma

nmohammed
Builder

@pavanae 

can you share your search query ? But you should be able to search the host like following - 

| inputlookup answers-571895.csv
| where Host="*"

 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...