Splunk Search

How to do a lookup on multiple values in a text file on an HTTP URL?

vivekriyer
Explorer

I have a requirement to be implemented in Splunk.

Facts:
I am a newbie to Splunk.

Problem Statement:
a. There is a text file in an http url that contains space delimited values (similar to a fixed length file).

b. The requirement is to do a lookup on this url, then load the values onto an index (these values get updated frequently and without notification).

c. Searched this community and the documentation, but couldn't quite find an answer.
https://answers.splunk.com/answers/69000/external-file-lookup-is-failing-possible-due-to-a-character...
https://answers.splunk.com/answers/10463/example-of-doing-an-external-lookup-using-http-get-or-post....
http://docs.splunk.com/Documentation/Splunk/6.1.4/Knowledge/Addfieldsfromexternaldatasources

d. Have considered using external_lookup.py (but doesn't accept a http url,that provides a text response, as an input)

e. I am not great inPython and need a quick turnaround.

Please advise the best solution for this scenario

0 Karma
1 Solution

woodcock
Esteemed Legend

vivekriyer
Explorer

Thank you for the quick reply. I will try this out and update this thread. Appreciate the help.

0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...