Splunk Search

How to load a list of values for a search from the GUI

larrywest
Explorer

How can I look for a list of 50+ values without typing in "foo=1 OR foo=29 OR foo=4219...".

Obviously without touching files on /opt/splunk/ anything, but as a normal file user.

I would like to load this from a file on my machine, a command something like inputcsv or inputlookup which, if I understand correctly, are restricted to looking on the Splunk server.

Tags (2)
0 Karma

lguinn2
Legend

It is true that inputlookup and inputcsv use files on the Splunk server. However, power users can upload files into Splunk using the lookup capability, and therefore use these commands. You don't have to be a Splunk admin.

0 Karma

larrywest
Explorer

SPLUNK: I can't edit my own question, just submitted moments ago, because the edit Captcha is broken. Tried 10+ times, most not difficult. Safari 7.0.3 on a Mac.

I would have changed the middle to say "without touching any files on /opt/splunk, but as a normal user"/

0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...