Splunk Search

CSV Lookup for search query

Abdulm1
Explorer

I have a search query like this

index=ppt sm.to{}="[email protected]" OR sm.to{}="[email protected]" |table sm.to{} sm.stat

and I want to use a csv lookup instead because I have more email address to use and I want the result to show this two fields .

My csv contains this
sm.to{}
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]

Can anyone help with a lookup search query for me . thanks.

0 Karma
1 Solution

manjunathmeti
Champion

Try this:

index=ppt | lookup .csv sm.to{} OUTPUT sm.to{} as sm_to | search sm_to = *

View solution in original post

manjunathmeti
Champion

Try this:

index=ppt | lookup .csv sm.to{} OUTPUT sm.to{} as sm_to | search sm_to = *

Abdulm1
Explorer

am actaully using inputlookup so i used the below command but it did not work

index=proofpoint sourcetype=pps_maillog | inputlookup smto OUTPUT sm.to{} as sm_to | search sm_to = *

I tried the following as well but did not work
index=ppt
| eval Recipients='sm.to{}'
| table Recipients
| search Recipients = "*"
| join type=inner Recipients
[| inputlookup smto
| table sm.to{} sm.stat]

0 Karma

Abdulm1
Explorer

Thanks @manjunathmeti it worked perfectly.

index=ppt | lookup .csv sm.to{} OUTPUT sm.to{} as sm_to | search sm_to = * | table sm_to sm.stat

0 Karma

manjunathmeti
Champion

May be it's due to field name, rename sm.to{} to smto in csv file and search query and try.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...