Splunk Search
Highlighted

How to pull out values from a lookup file based on user input without having to run any search commands or search through any logs?

New Member

I have created a dashboard that allows for a user to input a public IP address and based on the input, pull back any data associated with that IP into various panels. On one of the panels I would like to pull out the values from a lookup file that I have created based on the user input without having to do any search commands or search through any logs.

Sudo code
$x.x.x.x$ = user input token

srcip=$x.x.x.x$ | lookup iptable IP as src_ip OUTPUT Company, Location

0 Karma
Highlighted

Re: How to pull out values from a lookup file based on user input without having to run any search commands or search through any logs?

Path Finder

I am not sure if this answers your question because it involves a search. Maybe you could use inputlookup.

|inputlookup ip_table |where IP=$x.x.x.x$|fields Company, Location

View solution in original post

0 Karma
Highlighted

Re: How to pull out values from a lookup file based on user input without having to run any search commands or search through any logs?

New Member

Genius! It's so simple and that is exactly what I was looking didn't even think about using the where in the search. Thanks.

0 Karma
Highlighted

Re: How to pull out values from a lookup file based on user input without having to run any search commands or search through any logs?

New Member

Looking for more help on this. I came across this scenario when no results came back from the lookup table, but I still want to do something with the IP.

Ex.
| inputlookup tablename | where IP="x.x.x.x" | stats count | eval result=if(count==0, IP, Company) | iplocation IP | fields IP, Company, City, Region, Country

So basically if no results come back I still want to return the Geo information on the IP. If there are results then I want the results from the lookup and also return the Geo information.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.