Splunk Search

Creating Pivot Chart from Lookup/.CSV file

jfellows
New Member

I am trying to create a pivot chart from static data stored in a .CSV file. The data is not time-dependent and I am using a lookup to import the data into Splunk. When I access the lookup using |inputlookup datafile.csv in the Search and Reporting App, I am able to view the data, but am given limited options when trying make visualizations out of the search. When creating a data model using this lookup, I get the message "This dataset is not pivotable".

Is there a way to make this lookup dataset pivotable? Is this not possible with lookups? Currently I'm able to create a visualization, but without the customization I'd like when using data that is added when uploaded or monitoring files.

Tags (3)
0 Karma

rfitch
Path Finder

I ran into this when clicking on the pivot button from the data model page. Once I moved out and clicked on Datasets, I was able to build my pivot.

0 Karma

sloshburch
Ultra Champion

Yea, datasets are probably a better fit. A lookup is now considered a dataset type actually. http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutdatasets#Lookups

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...