Splunk Search

How to search with variables from lookup csv?

fishmong3r
Explorer

Let's say I have a search and a very basic lookup table (csv). What I want to achieve is to use the values in the table for my search.

So my table.csv:

id name
1 first
2 second
3 third

 

Now, I want to simply run a query like which returns every single log that has any of the id's from my lookup table.

index=myIndex sourcetype=mySourcetype id IN somelookup ---- where id is in table.csv's id column.

 

The second challenge then would be to actually have the name column values added as a field to the results for clarity.

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

fishmong3r
Explorer

For that, I get "Error in 'lookup' command: Must specify one or more lookup fields."

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup table.csv id
0 Karma

fishmong3r
Explorer

lovely!

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...