Splunk Search

How to append dynamic value to end of search?

ub_ik
Explorer

Dear Community

I am looking for a way to add a static and a dynamic value at the end of a search to track the status of the (saved) search. I would like to add the dynamic value to be extraced from an CSV-File.

 

|...base search...
| table index, sourcetype, _time.....

| append
    [ makeresults
    | eval status="completed"
    | eval ID = missionID<field from input.csv>   
    ]

 

Any help is appreciated.

 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
|...base search...
| table index, sourcetype, _time.....

| append
    [ | inputlookup input.csv 
    | eval status="completed"]

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Would something like this work for you?

|...base search...
| table index, sourcetype, _time.....

| append
    [ | makeresults
    | eval status="completed"   
    ]
| append
    [ | inputlookup input.csv ]
0 Karma

ub_ik
Explorer

Thx for your answer. Unfortunately not. I need the field from the lookup on the same line as

the other evals in the first append.

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
|...base search...
| table index, sourcetype, _time.....

| append
    [ | inputlookup input.csv 
    | eval status="completed"]
0 Karma

ub_ik
Explorer

life could be soo easy. thx a lot for your expertise.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...