Splunk Search

How to add multiple field values from a CSV to my main search?

queryboy
Explorer

I need to add multiple values from a CSV to a main Search I have, I used the lookup command but I think that will just compare one field from the main search and the CSV and I need to add more fields from the CSV to do some evals, Please help!

Labels (5)
0 Karma

queryboy
Explorer

can you please show me how to put it in splunk currently I have this: 

| lookup Hirings.csv  Last_Name AS Last

I need to add more fields from the CSV one of this fields is called "Search_Status" but I don't know how to set the syntax for this.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, the lookup command will return all fields from the lookup file that were not used as inputs.  If you want a selection of fields or want to make it clearer which fields are being obtained, then use the OUTPUT or OUTPUTNEW option.  The latter returns only the fields that don't already exist.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The lookup command can compare multiple fields and return multiple fields so it may work for you.  Please tell us more about your use case.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...