I use dbxquery and get this result from database:
Also I have a csv file already put in lookup of Splunk like this:
Please, how can I insert the column "type" from lookup to the search result above?
Basically this is what I want to achieve:
I tried: |lookup lookupfile.csv id OUTPUT id type but it doesn't work
Your lookup command should have worked, but try this one.
| lookup lookupfile.csv id OUTPUT type
If that doesn't produce the desired results then please show or explain the results you do get. "it doesn't work" isn't very helpful.
I agree that "doesn't work" is not informative and should be avoided in any description.
Additionally, when you "put in lookup of Splunk," did you make a lookup definition? (In addition to upload the CSV file.) Did you name that definition as "lookupfile.csv" or something else? (I usually name my lookups "lookupfile" instead of "lookupfile.csv".)