Splunk Search

How to search iterate through lookup file

chrisfilor
Engager

I have an input lookup table with a list of user accounts we are trying to search through.

Instead of doing index=wineventlog EventCode=4624 user=user1 OR user=user2 OR user=user3.....etc

How can I use the lookup table to search on the user field?

As of now, I have this but it is returning no results:

index=wineventlog_ad EventCode=4624 [inputlookup user_list_lookup.csv]
0 Karma
1 Solution

starcher
Influencer

Use lookups as lookups. and make sure the column name is the same as the user field in the data or use user AS userName or whatever the field is.

index=wineventlog_ad EventCode=4624 | lookup user_list_lookup user OUTPUT user as isFound | where isnotnull(isFound)

View solution in original post

starcher
Influencer

Use lookups as lookups. and make sure the column name is the same as the user field in the data or use user AS userName or whatever the field is.

index=wineventlog_ad EventCode=4624 | lookup user_list_lookup user OUTPUT user as isFound | where isnotnull(isFound)

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...