Splunk Search

DB Connect 1: Is it possible to get a new field using dbquery that does not exist in an index?

sfatnass
Contributor

Hi

I want to know if it's possible to get a new field from dbquery that does not exist in an index:

index=A 
[|inputlookup file.csv | table field_ip]
| join type=outer fieldA [dbquery ..."select......" |fields + fieldA |rename fieldA as fieldB]
|table fieldB

i tried this, but was not successful. fieldB doesn't exist in index=A, but i need it. How can i do it?

thx

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

The right way to do this is a dblookup.

0 Karma

sfatnass
Contributor

but the dblookup can return just the first matching line in my database

0 Karma
Get Updates on the Splunk Community!

Manual Instrumentation with Splunk Observability Cloud: The What and Why

If you've ever worked with distributed systems, you’ve likely felt the pain of a frontend throwing errors, ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...