Splunk Search

How to write a search to join the data from four lookups on a unique field?

New Member

Hello Experts,

Can you please help me with a search to join these four lookups on login (unique field). Lookups LOOKUP_A.CSV, LOOKUP_B.CSV, LOOKUP_C.CSV need to be joined to MASTER_lookup to form a RESULT_LOOKUP.

Appreciate your help with this.

Please check the source lookups and resultingdesired lookup. (attachment/inline image)

alt text

0 Karma


Another option?

| inputlookup  MASTER_LOOKUP.CSV | inputlookup LOOKUP_A.CSV append=t | inputlookup LOOKUP_B.CSV  append=t | inputlookup LOOKUP_C.CSV  append=t | outputlookup RESULT_LOOKUP.csv
0 Karma


What about this?

| inputcsv MASTER_LOOKUP.csv
| join type=left login [| inputcsv LOOKUP_A.csv]
| join type=left login [| inputcsv LOOKUP_B.csv]
| join type=left login [| inputcsv LOOKUP_C.csv]
| outputcsv RESULT_LOOKUP.csv
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...