Splunk Search

How to fetch mathed fileds values from index with lookup table ?


Hi Team,

I tried all possibilities to extract the data from index which are matched field values with lookup table .

the requirement is to pull the existing fields in  index=xxxxxx sourcetype=yyyy,  I can see many fields but  would like  path: /vol/xxxxxx/xxxxxxxx-lun0_xxxxxxxx/uswilo60-00.lun. we have number events but we only need 300 lunid along the some other filelds, like the highlighted part we have a lot but we need to pull the data of only 300-requored Lun.


I have created lookup table for those 300 lun but how to extract based on only these 300, we should pull path,volume,host,name….those exist in index but in lookup we are having only one column that lun.


could any one help on this


Labels (4)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...