Splunk Search

How do you rename rows using a CSV file?


Hi there,

I need a way to rename rows using a file list (csv file or other file type) from a search job / dashboard.

Thank you,

Tags (1)
0 Karma


|inputlookup mycsv | eval myrow=myoldname | fields - myoldname | outputlookup mycsv

0 Karma


I completely agree with valiquet

0 Karma


Hi valiquet,

I don't think this will gonna work because is a long list of process names and i want to rename name of the process from field .... if this make's any sense ...

I have something like this:

ProcessName Count of timestamp
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe 2
c:\program files (x86)\google\chrome\application\chrome.exe 1106273
c:\program files (x86)\google\update\googleupdate.exe 54

And i would like to have it like this:

ProcessName Count of timestamp
adobearm.exe 2
chrome.exe 1106273
googleupdate.exe 54

But also to be in live search in the dashboard.

First thought was to use a csv file because is easier to manage, but i think i could also go even deeper and edit index (?) or other file where i could find how is setting the process name (?)


0 Karma
Get Updates on the Splunk Community!

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...