Knowledge Management

what is the difference between inputcsv and inputlookup?

asmithe
Path Finder

From the documentation it looks that the difference is mostly the file location of the input file.

Can anyone with more experience with these two search commands comment on why you might choose to use inputlookup vs. inputcsv?

Tags (2)
1 Solution

araitz
Splunk Employee
Splunk Employee

inputlookup treats the given lookup as input. If CSV files, lookups must be in $SPLUNK_HOME/etc/apps//lookups. Otherwise, they might be scripted or external_url lookups, in which case a script or URL is providing said input.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Inputlookup

inputcsv treats the given CSV file as input. CSV files can only be used if they live in $SPLUNK_HOME/var/run/splunk.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Inputcsv

View solution in original post

MuS
SplunkTrust
SplunkTrust

@somesoni2: thanks for this hint! using append=t works, without you will get the must be first search command error 😉

araitz
Splunk Employee
Splunk Employee

inputlookup treats the given lookup as input. If CSV files, lookups must be in $SPLUNK_HOME/etc/apps//lookups. Otherwise, they might be scripted or external_url lookups, in which case a script or URL is providing said input.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Inputlookup

inputcsv treats the given CSV file as input. CSV files can only be used if they live in $SPLUNK_HOME/var/run/splunk.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Inputcsv

aelliott
Motivator

inputcsv can be treated as "events" by setting a flag that will allow for timecharts of the data.

0 Karma

somesoni2
Revered Legend

Are you sure it should be the first command, I guess we can do things like "index=_internal | inputcsv abc.csv append=t"

0 Karma

MuS
SplunkTrust
SplunkTrust

as addition:
inputcsv must be the first command in a search, where as a lookup can be done anywhere in the search path

0 Karma

somesoni2
Revered Legend

Portability of csv file can also be a factor for having a csv file added as lookup table file (under an app) so they can be deployed across various splunk instances as part of app package.

0 Karma

somesoni2
Revered Legend

One difference I can see is that you can restrict the execution of the command/access to csv data using role security using inputlookup. (inputlookup loads data from lookup table file/lookup definition file permissions for which can be set)

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...