Splunk Search

Can I write a CSV Lookup that's Partial Matching?

pagnihot
Path Finder

Dear All

I have a CSV lookup with a column name column1 with below values

 

MicroBest

GoDear

Bear

 

And I have some logs in which the field1 contains values like

MicroBest Infrastructure

No-GoDear-To-World

Lives The Life

I want to write a query that should match the first two events as lookup column value is a substring to field value. Also, I don't want to use *lookup_value* as it will also match something like Mi GoDearSamsung-Phone.

I

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can use WILDCARD matching in your lookup definition. This would require the csv to have the wildcarding in, e.g. *GoDear*, however, this does help you in your case because you haven't provided a way to distinguish between No-GoDear-To-World and Mi GoDearSamsung-Phone, such that one would match and the other not match.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...