Splunk Search

How to compare search results with lookup?

bosseres
Contributor

Hello, everyone!

During search I got table like this

time host user action result
12:24:06 host1 Alex action1 success
12:48:32 host2 Michael action2 fail

 

I have lookup users.csv, which looks like this

host user
host1 Alex
host2 George

 

I want to compare my table with lookup and if host and user matches, return my table (time, host, user, action, result), thus on this example I want to get in results table:

time host user action result
12:24:06 host1 Alex action1 success

 

(because in second line user not matches). Thank you in advance.

Labels (1)
Tags (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bosseres,

if you could share your search I could be more detailed, anyway, the inputlookup command in a subsearch is the solution for your need.

please try something like this (adapting to your search:

 

index=your_index [ | inputlookup users.csv | fields host user ]
| table time host user action result

 

I supposed that the columns of the lookup are host and user.

Ciao.

Giuseppe

bosseres
Contributor

solved problem, topic can be closed

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @bosseres,

if you solved the problem, you can accept the solution for the other people of Community.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma

bosseres
Contributor

found out the reason why it's not working

it's because there is no original field "user" in logs, I get user with rex command

 

so it works with | inputlookup ... | fields host, but not working with | inputlookup ... | fields host user

0 Karma

bosseres
Contributor

I've tried it, but not works, I need to filter after I got result in table

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...