Splunk Search

How to display only matching names from a CSV file with 2 fields?

infra2sec
Path Finder

Hi,

I'd like to have Splunk display only matching names from my .csv data source which has 2 fields.

I'd like to display only the names that are common from either field.

This is what I have and I am lost after this:

source="some.csv" host="somehost" sourcetype="csv" | 

I guess that the fields command might help, but I don't know where to begin.

So you understand what I am trying to do, I have a relative who is related to a bunch of people. Field A shows all the people she is related to. Field B is a list of all of my relatives. Whatever relative names match will help us find the common tie.

Thank you very much in advance!!

1 Solution

woodcock
Esteemed Legend

If I understand you correctly, after you configure your CSV as a lookup, maybe like this:

source="some.csv" host="somehost" sourcetype="csv" | lookup CSVlookup FieldA OUTPUT FieldB AS BfromA | lookup CSVlookup FieldB OUTPUT FieldA AS AfromB  | where isnotnull(AfromB) OR isnotnull(BfromA)

View solution in original post

woodcock
Esteemed Legend

If I understand you correctly, after you configure your CSV as a lookup, maybe like this:

source="some.csv" host="somehost" sourcetype="csv" | lookup CSVlookup FieldA OUTPUT FieldB AS BfromA | lookup CSVlookup FieldB OUTPUT FieldA AS AfromB  | where isnotnull(AfromB) OR isnotnull(BfromA)

infra2sec
Path Finder

I ended up using some excel functionality to make it happen. I can't quite remember what happened when I tried. Sorry that I forgot to come back and provide feedback.

I appreciate the help.

0 Karma

woodcock
Esteemed Legend

You click Accept on this answer (hopefully after adding a bit more detail) to close the Question.

0 Karma

infra2sec
Path Finder

Thanks, will try it. I think we have a close understanding.

0 Karma

woodcock
Esteemed Legend

Did it work?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...