Splunk Search

Compare search field to similar field in lookup1 then compare to field in lookup2

becksyboy
Contributor

Hi i'm having trouble trying to to do the following:

I have a search which pulls the event_id, which i would like to compare against the first lookup_file1 [alert_id] which contains a column called alert_id, and in turn list the associated severity values from the next column.

lookup1 = alert_id
(col names)
alert,alert,id,class,severity

I would then like to compare the above results to lookup_file2 [alert_severity] and take the previous severity values and list the severity_message

lookup2 = alert_severity
(col names)
severity,severity_message

Past Attempts:

index="zsecure_test" | fields alert_id
|lookup alert_id alert_id | dedup alert_id |append [lookup alert_severity severity_message]|table alert_id, class, severity, severity_message

index="zsecure_test" | fields alert_id
|lookup alert_id alert_id | dedup alert_id |table alert_id, class, severity
|append [inputlookup alert_severity | fields + severity_message]

thanks

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi becksyboy,
use two times lookup command

index="zsecure_test" 
| fields alert_id
| dedup alert_id 
| lookup alert_id alert_id OUTPUT class severity
| lookup alert_severity severity OUTPUT severity_message 
| table alert_id class severity severity_message

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi becksyboy,
use two times lookup command

index="zsecure_test" 
| fields alert_id
| dedup alert_id 
| lookup alert_id alert_id OUTPUT class severity
| lookup alert_severity severity OUTPUT severity_message 
| table alert_id class severity severity_message

Bye.
Giuseppe

0 Karma

becksyboy
Contributor

Thanks Giuseppe! works great

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...