How do lookups work in Splunk?
I presume it works like this, lookupA
is the value you are looking for and ValueToReplaceLookup
is the value that is returned.
lookupA,ValueToReplaceLookup
A,America
B,Beijing
C,Columbia
But can it also work this way; looking up a value and the value is returned is to the left of it. E.g. lookupA
is the value you are looking for and ValueToReplaceLookup
is the value that is returned, but ValueToReplaceLookup
will be on the left as opposed to the right?
ValueToReplaceLookup,lookupA,
America,A
Beijing,B
Columbia,C
Just wondering if I should be formatting my data accordingly before uploading it to Splunk for doing lookups.
Luckily, Splunk is not Excel. Lookups work per line, not from left to right, so the order of colums doesn't matter at all.
Did you know you can also lookup more than one value? And that you can write your own .csv file from splunk with one search and look stuff up there with another search? Lookup in Splunk is actually fun! 🙂
Luckily, Splunk is not Excel. Lookups work per line, not from left to right, so the order of colums doesn't matter at all.
Did you know you can also lookup more than one value? And that you can write your own .csv file from splunk with one search and look stuff up there with another search? Lookup in Splunk is actually fun! 🙂
tks, good to know, now I just need to find examples where I can use that them other ways you mention of using lookups
this here might be an example of how I can apply lookups further mentioned above?
You don't have to format it. Column position does not matter.