Splunk Search

How do you rename rows using a CSV file?

bogdan_nicolesc
Communicator

Hi there,

I need a way to rename rows using a file list (csv file or other file type) from a search job / dashboard.

Thank you,
Bogdan.

Tags (1)
0 Karma

valiquet
Contributor

|inputlookup mycsv | eval myrow=myoldname | fields - myoldname | outputlookup mycsv

0 Karma

iamarkaprabha
Contributor

I completely agree with valiquet

0 Karma

bogdan_nicolesc
Communicator

Hi valiquet,

I don't think this will gonna work because is a long list of process names and i want to rename name of the process from field .... if this make's any sense ...

I have something like this:

ProcessName Count of timestamp
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe 2
c:\program files (x86)\google\chrome\application\chrome.exe 1106273
c:\program files (x86)\google\update\googleupdate.exe 54

And i would like to have it like this:

ProcessName Count of timestamp
adobearm.exe 2
chrome.exe 1106273
googleupdate.exe 54

But also to be in live search in the dashboard.

First thought was to use a csv file because is easier to manage, but i think i could also go even deeper and edit index (?) or other file where i could find how is setting the process name (?)

Thnx.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...