Splunk Search

How to use 2 columns in one join search

Eyal
Path Finder

Hi,

I have a query that trigger when a user has been added to a specific types of groups.

The query depends on lookup with 2 columns inside (one for group_name, Another for Severity).

I want to find any event of adding to one of the monitored groups, But also to enrich my final table with the severity right next to the group_name.

I have tried to resolve this using:

| join type=left group_name
[| inputlookup my_list.csv]
| where isnotnull(Severity)

But somehow only 2 groups with low severity is being found even though all the groups in the list has its own severity.

How can I managed to make my table show the group with its severity?

Labels (2)
Tags (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @Eyal,

for joinining a lookup you don't need the join command that anyway shoud be avoided all the times and used only when there isn't any other solution.

You can use the lookup command that's a left join, something like this:

<your_search>
| lookup my_list.csv group_name OUTPUT Severity
| where isnotnull(Severity)

if the field to use gor joining is different beteen the main swarch and the lookup, you can use AS.

for more infos see at https://docs.splunk.com/Documentation/Splunk/9.1.1/SearchReference/Lookup

Ciao.

Giuseppe

View solution in original post

Eyal
Path Finder

Hi Giuseppe thank you for your help it worked 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Eyal,

for joinining a lookup you don't need the join command that anyway shoud be avoided all the times and used only when there isn't any other solution.

You can use the lookup command that's a left join, something like this:

<your_search>
| lookup my_list.csv group_name OUTPUT Severity
| where isnotnull(Severity)

if the field to use gor joining is different beteen the main swarch and the lookup, you can use AS.

for more infos see at https://docs.splunk.com/Documentation/Splunk/9.1.1/SearchReference/Lookup

Ciao.

Giuseppe

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...