Splunk Search

How to add new entries in lookup?

bosseres
Contributor

Hello, everyone!

I have search, which ends in such way

...

| table id, name
| outputlookup my_lookup.csv


so my search get such results

id name
1 John
2 Mark
3 James


Now, I want to record only NEW id's from search  to lookup, which weren't there

Is it possible to make without reworking search?

Labels (3)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

append=t

You should remove any results which are already in your lookup.

bosseres
Contributor

append true makes dublicates, is it possible to avoid it?

maybe any other solution?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes, as I said, remove the duplicates before the outputlookup.

It does depend on how you generate the events you want to add to the lookup.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bosseres,

you have two choices:

  • fully override the lookup,
  • add new names.

For the second choice, please try this:

<your_search> NOT [ | inputlookup my_lookup.csv | fields name ]
| table id, name
| outputlookup my_lookup.csv append=true

Ciao.

Giuseppe

bosseres
Contributor

Ye, I thought about it, but...

first one choice is not suit to me, because I need to make big time range of search to collect of actual id's.

about second one I thought, but i am afraid of some id's can be changed, so better to recollect them

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...