Splunk Search

How to compare the value of a field (search) with the value of a csv field when you have to adapt a field first

christianubeda
Path Finder

Hello team!

I would like to ask you a question since I have been thinking about it for a while and I am not getting it

I want to compare the user field of my search with the REGISTER field of my csv. The problem is that I have to adapt the user field first to be similar to REGISTER

I have tried with

search  | eval user=split(user,"\\")  |  lookup csvfile.csv REGISTRO as usern | values(user) .... | where user=usern

Can`t with inputlook cause I have to | eval user=split(user,"\\")  first

[| inputlookup csvfile.csv
| rename REGISTRO as usern
| fields usern]

user field is like aaaa111

and REGISTER is like XXX\aaaa111

 

Thank you!

Labels (4)

rupkumar4sec
Path Finder

@christianubeda 
If your 
user field is like “aaaa111” and REGISTER is like “XXX\aaaa111”, why are you splitting user field? If what I understood is correct, your eval should be on the lookup field(Register). 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @christianubeda ... i am not much clear of your issue.. 

but i can try to edit this query...

search  | eval user=split(user,"\\")  |  lookup csvfile.csv REGISTRO as usern | values(user) .... | where user=usern 

should be / could be ....

base-search  | eval user=split(user,"\\")  | join [lookup csvfile.csv REGISTRO as usern] | stats values(user) AS UserNames .... | where user=usern 
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...