Splunk Search

How to compare a field to another field in a CSV file?

Contributor

I need to lookup the IP in a firewall log to a field in an inputcsv. The CSV file holds 50k results, so subsearches are limited. It's been recommended not to increase the subsearch event limit in limits.conf. I've thought about doing the lookup using a relational database, but I would like to do this in the Splunk environment if possible. Does anyone have any suggestions?

0 Karma
1 Solution

Legend

Legend

Contributor

lookup tables with updater reports as suggested by Sundareshr.

0 Karma

Contributor

Works way better than I had expected. Thank you!

0 Karma

Legend

Yes, 50K results is definitely in range of a static lookup, as @sundareshr points out

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!