Splunk Search

How to fetch mathed fileds values from index with lookup table ?

90509
Engager

Hi Team,

I tried all possibilities to extract the data from index which are matched field values with lookup table .

the requirement is to pull the existing fields in  index=xxxxxx sourcetype=yyyy,  I can see many fields but  would like  path: /vol/xxxxxx/xxxxxxxx-lun0_xxxxxxxx/uswilo60-00.lun. we have number events but we only need 300 lunid along the some other filelds, like the highlighted part we have a lot but we need to pull the data of only 300-requored Lun.

 

I have created lookup table for those 300 lun but how to extract based on only these 300, we should pull path,volume,host,name….those exist in index but in lookup we are having only one column that lun.

 

could any one help on this

 

Labels (4)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...