Splunk Search

How to compare the value of a field (search) with the value of a csv field when you have to adapt a field first

christianubeda
Path Finder

Hello team!

I would like to ask you a question since I have been thinking about it for a while and I am not getting it

I want to compare the user field of my search with the REGISTER field of my csv. The problem is that I have to adapt the user field first to be similar to REGISTER

I have tried with

search  | eval user=split(user,"\\")  |  lookup csvfile.csv REGISTRO as usern | values(user) .... | where user=usern

Can`t with inputlook cause I have to | eval user=split(user,"\\")  first

[| inputlookup csvfile.csv
| rename REGISTRO as usern
| fields usern]

user field is like aaaa111

and REGISTER is like XXX\aaaa111

 

Thank you!

Labels (4)

rupkumar4sec
Path Finder

@christianubeda 
If your 
user field is like “aaaa111” and REGISTER is like “XXX\aaaa111”, why are you splitting user field? If what I understood is correct, your eval should be on the lookup field(Register). 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @christianubeda ... i am not much clear of your issue.. 

but i can try to edit this query...

search  | eval user=split(user,"\\")  |  lookup csvfile.csv REGISTRO as usern | values(user) .... | where user=usern 

should be / could be ....

base-search  | eval user=split(user,"\\")  | join [lookup csvfile.csv REGISTRO as usern] | stats values(user) AS UserNames .... | where user=usern 
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...