Splunk Search

Creating Pivot Chart from Lookup/.CSV file

jfellows
New Member

I am trying to create a pivot chart from static data stored in a .CSV file. The data is not time-dependent and I am using a lookup to import the data into Splunk. When I access the lookup using |inputlookup datafile.csv in the Search and Reporting App, I am able to view the data, but am given limited options when trying make visualizations out of the search. When creating a data model using this lookup, I get the message "This dataset is not pivotable".

Is there a way to make this lookup dataset pivotable? Is this not possible with lookups? Currently I'm able to create a visualization, but without the customization I'd like when using data that is added when uploaded or monitoring files.

Tags (3)
0 Karma

rfitch
Path Finder

I ran into this when clicking on the pivot button from the data model page. Once I moved out and clicked on Datasets, I was able to build my pivot.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Yea, datasets are probably a better fit. A lookup is now considered a dataset type actually. http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutdatasets#Lookups

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...