I have 2 separate queries as below:
Query1: (normal splunk search e.g. index=* host=abcde | table Message1,Message2,Status ....)
Message1, Message2, Status
Query2: (using inputlookup blabla.csv | table Status,Action)
How do i map both queries above and produce output as below:
Basically the Status from Query1 needs to be mapped with Query2 and output the corresponding action.
Appreciate the help!
What are the actual column names in the lookup table? Is it "Status" and "Action" (Starting with capital letter)?
Also the fields from Query 1?
In the lookup table the headers are:
For query1 it is as below:
The "status" field from query1 is produced from a rex command.
So, there is no "Status" field in the Lookup, that's why it didn't map.
I assume the field "Error_Code" is what you want to map with the "Status" from Query 1.
| lookup blabla.csv Status as "Error_Code" OUTPUT Action
Not to worry, i found the solution!
The Error_Code (i have renamed this to Status) in Query 2 was in uppercase whereas the Status in Query 1 was in lowercase. After matching them to either upper/lower case, i managed to get the desired output based on your lookup recommendation.
Thanks anyways! 😃