Splunk Search

How do you rename rows using a CSV file?

bogdan_nicolesc
Communicator

Hi there,

I need a way to rename rows using a file list (csv file or other file type) from a search job / dashboard.

Thank you,
Bogdan.

Tags (1)
0 Karma

valiquet
Contributor

|inputlookup mycsv | eval myrow=myoldname | fields - myoldname | outputlookup mycsv

0 Karma

iamarkaprabha
Contributor

I completely agree with valiquet

0 Karma

bogdan_nicolesc
Communicator

Hi valiquet,

I don't think this will gonna work because is a long list of process names and i want to rename name of the process from field .... if this make's any sense ...

I have something like this:

ProcessName Count of timestamp
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe 2
c:\program files (x86)\google\chrome\application\chrome.exe 1106273
c:\program files (x86)\google\update\googleupdate.exe 54

And i would like to have it like this:

ProcessName Count of timestamp
adobearm.exe 2
chrome.exe 1106273
googleupdate.exe 54

But also to be in live search in the dashboard.

First thought was to use a csv file because is easier to manage, but i think i could also go even deeper and edit index (?) or other file where i could find how is setting the process name (?)

Thnx.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...