I'm a new user of Splunk 6.5.7. I have a search but only want results for 288 specific customerIDs. This would be a very long list of ORs and i don't think 6.5.7 supports an IN function.
So I want a table output like with two columns from my search - CustomerName, CustomerID
But only where the customerID is in my csv of customerIDs. I feel I should be able to do this using a lookup but just can't get it right. Anyone able to help please?
Hi @Poacher,
Please try below options;
| your_search [|inputlookup customerids.csv | fields customerID]OR
| your_search
| lookup customerids.csv customerID OUTPUT customerID AS valid
| where isnotnull(valid)
| fields - valid
Thank you