Splunk Search

Can you add dynamically to your events when theres a match in lookup?

ashishlal82
Explorer

I have a static or .csv file that lookups with a field in the events. If there is a match It should create a field dynamically and assign a certain value ( 0 or 1) , without using automatic lookup and adding a field in .csv field.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You've got a solution in your question already - add an output field to your lookup, and define an automatic lookup on your data.

If for some reason you cannot change the .csv file as it comes in, you could define a scheduled search that periodically reads the immutable .csv via inputlookup, adds the output field via eval, and writes that to a second .csv via outputlookup. That second .csv gets used in the automatic lookup.
Is there any other reason why you don't want to use the obvious solution you already found?

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...