Splunk Cloud Platform

Splunk Cloud | CSV input data search

SK2007
Loves-to-Learn Lots

Hi Team,

Could you please help me with below query, I have CSV file which contain correlation id's (1000+ records) in single column.  I need provide this CSV to Splunk search as input and search each correlation id's  and display the results/events related to those correlation Id's.  We are using Splunk Cloud and do please let me process o how can  I can achieve this?

Labels (1)
0 Karma

SK2007
Loves-to-Learn Lots

Hi Could anyone help me with above query?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Take a look at this on how to use inputlookup to achieve what you are after. Adjust to your event and lookup field names as appropriate.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...