Splunk Search

Compare two field values and get matching third value from table

ckunath
Communicator

Hello,

i'm trying to do a search and then compare my result with a table from a .csv file (contains a table with ids and text for each id).
My search:

index=foo eventid=200 | append [|inputlookup ids.csv] | table eventid id text

This gets me a table like this:

eventid | id | text
10      |    |
        | 1  | text1
        | 2  | text2

[...]

How can I change my search to make the table look like this?

id | text
10 | text10

Thanks in advance!

Tags (4)
0 Karma
1 Solution

lguinn2
Legend

If you want to get a matching value from a table, you need to use the lookup command.

 index=foo eventid=200 
| lookup ids.csv eventid as id OUTPUT id text
| table eventid id text

View solution in original post

lguinn2
Legend

If you want to get a matching value from a table, you need to use the lookup command.

 index=foo eventid=200 
| lookup ids.csv eventid as id OUTPUT id text
| table eventid id text

ckunath
Communicator

Thanks a lot for the quick response! Works as intended.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...