Splunk Search

Does csv file accepts * symbol for lookup?

mikeyty07
Communicator

I have apis which has params in between and trying to  match the api from csv but it doesnt show when using lookup.

eg : /serviceName/api/127364/api   which is shown in access logs 
i have /serviceName/api/*/api in my csv file. 

Any idea how this works?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You have to create a lookup definition with WILDCARD matching

Define a CSV lookup in Splunk Web - Splunk Documentation

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...