Splunk Search

How to search with variables from lookup csv?

fishmong3r
Explorer

Let's say I have a search and a very basic lookup table (csv). What I want to achieve is to use the values in the table for my search.

So my table.csv:

id name
1 first
2 second
3 third

 

Now, I want to simply run a query like which returns every single log that has any of the id's from my lookup table.

index=myIndex sourcetype=mySourcetype id IN somelookup ---- where id is in table.csv's id column.

 

The second challenge then would be to actually have the name column values added as a field to the results for clarity.

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

fishmong3r
Explorer

For that, I get "Error in 'lookup' command: Must specify one or more lookup fields."

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup table.csv id
0 Karma

fishmong3r
Explorer

lovely!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...