Splunk Search

How to compare two lookup files and get two coloumns in serch

Dheeraj25
Engager

I have two lookups B1.csv and B2.csv. B1 has block member and B2 has block id and both have one same column departments. I want to compare these both with departments and get matching values of Block member and BLOCK ID. I also have index Z from which I am done search along with my two looks ups 

B1:
BlockMember --- Department--email
B2:
BlockID --Department

Index and B1 has email as same values so I used "lookup B1.csv" email command and got block member in my table but now I am not sure how to get blockid from b2. 

My current search

index=Z  pipename=static-website*
|lookup b1 email
|rename member AS BlockMember (got this blockmember from above lookup b1 using email from my index)
|stats count by grid BlockMember  Status

current table:
grid----status--Blockmember

so my future table should be 
grid----status--BlockID--Blockmember(which will have same department)

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The two lookups can be matched using inputlookup and stats.

| inputlookup B1.csv
| inputlookup append=true B2.csv
| stats values(*) as * by Department
---
If this reply helps you, Karma would be appreciated.

Dheeraj25
Engager

Thanks but I also have an index that does the lookup with B1. I had updated my question above .. can you check and suggest ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Just add another lookup command for B2.  It looks like it doesn't matter, though, since the query only uses the grid, member, and Status fields.

index=Z  pipename=static-website*
|lookup b1 email
|lookup b2 department
|rename member AS BlockMember (got this blockmember from above lookup b1 using email from my index)
|stats count by grid BlockMember  Status

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...