Splunk Enterprise

How to search ingesting data in lookup?

smanojkumar
Contributor

I would like to know about to add a single field value to outputlookup, as currently there are some fields like id, condition, value is there , but the need is only to ingest condition, Can anyone provide the query for this.

0 Karma
1 Solution

marysan
Communicator

inputlookup mylookup.csv
|fields condition
|outputlookup mylookup.csv (OR  outputlookup mylookup2.csv)

View solution in original post

marysan
Communicator

inputlookup mylookup.csv
|fields condition
|outputlookup mylookup.csv (OR  outputlookup mylookup2.csv)

richgalloway
SplunkTrust
SplunkTrust

The inputlookup command does have a way to specify which field(s) to return.  You can, however, use the fields command for that.

| inputlookup mylookup.csv | fields condition

 

---
If this reply helps you, Karma would be appreciated.

smanojkumar
Contributor

Hi @richgalloway ,

    It is kind of storing data in lookup, so for storing data in lookup that should be one field, so that i mentioned outputlookup.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thank for that.  You also mentioned "ingest" twice so no wonder I mis-understood.

Lookup files must be updated in their entirety.  You cannot replace a single row or field.  @marysan has the right answer for replacing the entire lookup with a single column.

To be able to updated individual fields in a lookup, use a KVStore collection.

---
If this reply helps you, Karma would be appreciated.

marysan
Communicator

Hi

there is some ways to update just one field in a lookup
for example we have a lookup with (IP,reported) fields
if you want to change reported field from 0 to 1 just for a specific IP,for example IP:1.2.3.4 , and you dont want to change other values :
|inputlookup mylookup.csv
|eval reported=if(IP="1.2.3.4",0,reported)
|outputlookup mylookup.csv

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is the method for updating a lookup file, but to be clear, the outputlookup command rewrites the entire lookup even if only a single bit is different.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...