Splunk Search

Can you add dynamically to your events when theres a match in lookup?


I have a static or .csv file that lookups with a field in the events. If there is a match It should create a field dynamically and assign a certain value ( 0 or 1) , without using automatic lookup and adding a field in .csv field.

0 Karma


You've got a solution in your question already - add an output field to your lookup, and define an automatic lookup on your data.

If for some reason you cannot change the .csv file as it comes in, you could define a scheduled search that periodically reads the immutable .csv via inputlookup, adds the output field via eval, and writes that to a second .csv via outputlookup. That second .csv gets used in the automatic lookup.
Is there any other reason why you don't want to use the obvious solution you already found?

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!