Splunk Search

How to fetch mathed fileds values from index with lookup table ?

90509
Engager

Hi Team,

I tried all possibilities to extract the data from index which are matched field values with lookup table .

the requirement is to pull the existing fields in  index=xxxxxx sourcetype=yyyy,  I can see many fields but  would like  path: /vol/xxxxxx/xxxxxxxx-lun0_xxxxxxxx/uswilo60-00.lun. we have number events but we only need 300 lunid along the some other filelds, like the highlighted part we have a lot but we need to pull the data of only 300-requored Lun.

 

I have created lookup table for those 300 lun but how to extract based on only these 300, we should pull path,volume,host,name….those exist in index but in lookup we are having only one column that lun.

 

could any one help on this

 

Labels (4)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...