Splunk search query :
index="something" | search hostname=variable
Please help.
Thanks in advance
With a subsearch
, like this:
index="something" AND [|inputlookup YourLookupNameHere.csv | table hostname | format]
Are you asking for how to reference a csv based on a variable value? There is a lookup
command https://docs.splunk.com/Documentation/Splunk/7.3.2/SearchReference/Lookup#Basic_example that you can use - in this case the syntax would look something like:
base search...
| lookup csvName.csv variable OUTPUT fieldsToOutput
In this case variable is the joining field between the csv and the base search, and you can OUTPUT whatever fields you want from that row (comma separated list).
Does this answer your question?