Splunk Search

Does csv file accepts * symbol for lookup?

mikeyty07
Communicator

I have apis which has params in between and trying to  match the api from csv but it doesnt show when using lookup.

eg : /serviceName/api/127364/api   which is shown in access logs 
i have /serviceName/api/*/api in my csv file. 

Any idea how this works?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You have to create a lookup definition with WILDCARD matching

Define a CSV lookup in Splunk Web - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...