Splunk Enterprise

Using a lookup to search another lookup

jwhughes58
Contributor

I have two lookups.  One consists of the allowed URLs.  The other consists of the URLs from a firewall.  For example in the first

 

google.com
dummy.com

 

 In the second

 

site1.google.com
site2.google.com

 

The first lookup is ingested from a file sent by the FW team.  I create the second lookup with this search

 

index=my_firewall sourcetype=my_sourcetype (rule=rule_1 OR rule=rule_2 OR rule=rule_3) [ | inputlookup external_url.csv ]
| fields url
| dedup url
| table url
| outputlookup external_results.csv

 

 This gives me the sites that have been reached over the time period.  Next I use this search

 

| inputlookup external_url.csv
| lookup external_results.csv url OUTPUTNEW url as isFound

 

I think this is giving me what I want, but I can't view the output the way I want.  I would like to see

 

allowed_url   fw_url   isFound

 

Using the sample data

 

google.com   site_1.google.com   true
google.com   site_2.google.com   true
dummy.com                        false

 

TIA,

Joe

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

With a little massaging of fields, we can get you the desired output.

| inputlookup external_url.csv
| lookup external_results.csv allowed_url as url OUTPUTNEW url as isFound
| eval fw_url=isFound, isFound=if(isnull(isFound),"false", "true")
| table allowed_url fw_url isFound
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...