Splunk Search

How to use a list of values from a table into foreach fieldstr?

danielearangiom
Explorer

Hi,
I already used the following lines with success:

| foreach fieldstr=device "device_name1" "device_name2" "device_name3" "device_nameN" 
    [ eval device= "<<FIELD>>"]

But, is it possible to pass a list of my devices name from a lookup table? I mean, something like:

| foreach fieldstr=device inputlookup devices_list.csv
    [ eval device= "<<FIELD>>"]

With devices_list.csv as:

device
...
device_name1
device_name2
device_name3
device_nameN

Tags (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @danielearangiomazza,
I don't understand your question properly, if you can give query before foreach or sample input-output so I can help you.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...