Splunk Search

Do a lookup with results of another lookup

Explorer

Does anyone know if this is possible? I have a search that works that gives me results for a particular user from a csv.

| inputlookup ldapsearch_corporate_identities | search identity="particular userid"

This lookup gives me the AD information for "particular userid".

I have another csv being generated with a list of userids that we want to pull information for. I'm wondering if I can get the first search to run and return results for each user listed in the second csv. Below is what I have so far. The search itself does list each userid in my csv. But I can't seem to get them to work together. Each user id is listed in a column called target_userid.

| inputlookup ldapsearch_corporate_identities|search [|inputlookup machines.csv |fields target_userid | dedup target_userid | mvexpand target_userid] | search identity=target_userid

0 Karma
1 Solution

Revered Legend

Try something like this

|inputlookup machines.csv |fields target_userid | dedup target_userid | mvexpand target_userid | lookup ldapsearch_corporate_identities identity as target_userid 

This will fetch the corresponding AD information for each target_userid.

View solution in original post

Explorer

Thanks to both of you for the suggestions. This worked perfectly!

0 Karma

Revered Legend

Try something like this

|inputlookup machines.csv |fields target_userid | dedup target_userid | mvexpand target_userid | lookup ldapsearch_corporate_identities identity as target_userid 

This will fetch the corresponding AD information for each target_userid.

View solution in original post

SplunkTrust
SplunkTrust

You should be able to do something like this:

| inputlookup ldapsearch_corporate_identities | search [inputlookup machines.csv | fields target_userid | dedup target_userid | rename target_userid as identity]

I'm a little confused about your mvexpand though, does the machines.csv contain multivalue target_userid fields?

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!