Splunk Search

How do i create another field based on existing naming convention

Path Finder

I have a raw event from where i want to capture a few specific fields already configured in splunk and want to create a kind of lookup data which will capture a record from an existing field and outlined based on lookup instruction.

aaad00 – if d, it should be captured under data
aaan00 – if n, it should be captured under name

0 Karma


At the highest level simply append | outputlookup my_lookup_name.csv to the end of your search. That said can you share a bit more on what it is you are trying to capture with some examples of the data or the desired state?

0 Karma