Splunk Search

Appending Lookup Match to Search Results

driva
Path Finder

Hi all,

I have a search that filters results based on a lookup file. Is there a simple way that I can add the match from the lookup file to the table/results?

index=web[| inputlookup HighRiskWords.csv | eval HighRiskWords="*"+HighRiskWords+"*" | rename HighRiskWords as web_Search] | stats count by web_Search, web_User, _time

It would be great to have the final piece of the search to be: Web_Search, {web_MatchingLookup}, web_user, _time

Thanks!

0 Karma

13tsavage
Communicator

Can you elaborate and provide more details to what exactly you are trying to do?

0 Karma

starcher
Influencer

don't do that. use a lookup as a lookup and make it a wildcard match type.

index=web 
| lookup HighRiskWords web_Search outputnew web_Search as isFound
| where isnotnull(isFound)
| stats count by web_Search, web_User, _time
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...