Splunk Search

Automatic Lookup not working

gokulakrishnans
Explorer

I've followed http://docs.splunk.com/Documentation/Splunk/latest/User/CreateAndConfigureFieldLookups and looked at plenty of questions about the same topic on here and I still can't figure out what I'm doing wrong with my automatic lookup. I also watched a video on this but it didn't really show how the lookup was created.

Here's my csv file I want to use for a file based lookup:

Error_Desc.csv

ErrorCode,description
1,A
2,A
3,A
4,A

For Lookup Table Files I selected
this csv and gave it the same name
for Destination filename.

For Lookup Definitions, destination app is "search", name is "WAT_Lookups.csv", type is "file based", and the lookup file is "Error_Desc.csv".

For Automatic Lookups, I have the following

Lookup Table: Error_Desc)=
Lookup input fields - ErrorCode=ABCD.ReturnCode
Lookup Output fields - Description = Description
Apply to : sourcetype named ****

Query I used to search is index=*** sourcetype=*** |table ErrorCode Description. If I run this query I get the coulmns but black table. Not sure how to proceed.

martin_mueller
SplunkTrust
SplunkTrust

Your lookup file has a lowercase field description, your automatic lookup expects an uppercase field Description.

gokulakrishnans
Explorer

Fine. I will correct that. Please clarify me the following.

Lookup Table: Error_Desc
Lookup input fields - ErrorCode=ABCD.ReturnCode (or) ErrorCode (or) ReturnCode
Lookup Output fields - Description = Description "Do I have to make any modifications in this"
Apply to: sourcetype named

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...