Splunk Search

Can you add dynamically to your events when theres a match in lookup?

ashishlal82
Explorer

I have a static or .csv file that lookups with a field in the events. If there is a match It should create a field dynamically and assign a certain value ( 0 or 1) , without using automatic lookup and adding a field in .csv field.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You've got a solution in your question already - add an output field to your lookup, and define an automatic lookup on your data.

If for some reason you cannot change the .csv file as it comes in, you could define a scheduled search that periodically reads the immutable .csv via inputlookup, adds the output field via eval, and writes that to a second .csv via outputlookup. That second .csv gets used in the automatic lookup.
Is there any other reason why you don't want to use the obvious solution you already found?

Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...

New Splunk Innovations Enhance Performance and Accelerate Troubleshooting

Splunk is excited to announce new releases that empower ITOps and engineering teams to stay ahead in ever ...