How do I associate the CSV file content generated by the outputcsv command with index data?

Path Finder

Now I have to get a CSV file from an outputcsv command :

index="fortify"| stats values(Codelocation) as codelocation by source | rename source as source_yy| outputcsv three.csv

and I can get a outputcsv like this :

 codelocation              source_yy
/root/taw/a                a_such.xml
/home/wxy/bc           b_code.xml

I have the following index data :


Now, I want to use the outputcsv command to get a outputcsv file containing codeL,sys_name,source_yy

like these :

     codeL                      sys_name                   source_yy
/root/taw/a                 project_1                    a_such.xml
/home/wxy/bc            project_2                    b_code.xml

codeL and codelocation have the same content.

What should I do?

0 Karma


I do not think that CSV is necessary.
You can edit it like this.

index="fortify"| stats values(Codelocation) as codeL  by source 
| rename source as source_yy
| join codeL  [search ( index data )| extract pairdelim=";", kvdelim="="]
| table codeL sys_name source_yy

※If you use CSV

( index data )| extract pairdelim=";", kvdelim="="]
 | join codeL  [search |inputcsv three.csv|renmae codelocation as codeL]
    | table codeL sys_name source_yy]
0 Karma

Path Finder

Thank you very much!

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>