Reporting

table question to add addtional columns/fields

omun0z
Explorer

Hello, I'm trying to add additional columns/fields from an additional CSV table lookup at the end of the table part in a search syntax to create a Report as below, but I'm not sure if that is possible as is not working, I just get a couple of blank additional columns with some error names.

sourcetype=ib:ipam:network index=ib_ipam | eval dedup_key=view."/".address."/".cidr | dedup dedup_key | eval Network_CIDR=address."/".cidr | search view = "Ashland" | ................................................................................................ | table Timestamp, "Network View", Network, CIDR, Total, Allocated, Reserved, Assigned, Protocol, "Utilization %", Unmanaged, [|inputlookup Ashland-Networks-EAs.csv |search Network = Network_CIDR |table Network, Region_DDI]

Any help would be very appreciated.

Thanks,

Omar.

Labels (1)
Tags (1)
0 Karma
1 Solution

omun0z
Explorer

Thank you so much!! It worked.

View solution in original post

0 Karma

omun0z
Explorer

Hi to4kawa, I tried to add [|inputlookup Ashland-Networks-EAs.csv |search Network = Network_CIDR |table Network, Region_DDI]  in the table part to add additional columns/fields based on the comun column Network_CIDR....  I think this is not the correct way, but not sure if this is possible.

 

Thanks,

 

Omar.

0 Karma

to4kawa
Ultra Champion
0 Karma

omun0z
Explorer

Thank you so much!! It worked.

0 Karma

to4kawa
Ultra Champion

sample:

|makeresults | table[| inputlookup geo_attr_countries.csv | table iso2 iso3]

This can't work.

your sub search can't work.  What do you want to do? 

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...