Splunk Search

Automatic Lookup to Overwrite Field Value at Search Time

agodoy
Communicator

I am trying to overwrite a field that is boolean. I created a table to convert 1/0 to IN/OUT so that the data is more human readable.

Below is my props.conf entry.

[source::mysource]
LOOKUP-mylookup = lookup_table direction_inbound AS direction_inbound OUTPUT direction AS direction_inbound 

I have tried:

LOOKUP-mylookup = lookup_table direction_inbound AS direction_inbound OUTPUTNEW direction AS direction_inbound 

with no positive results. Transforms.conf has the path to the csv. The lookup works if I create a new field, but I want to overwrite the field that is already there.

Any idea what I might be missing.

Tags (1)
0 Karma

niemesrw
Path Finder

Not sure when it was introduced, but you can now overwrite fields:

http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Lookup

0 Karma

cheganbm
Explorer
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...