Splunk Search

I have two tables "order.csv" and "delivery.csv". How can I use lookup command to check the delivery status based on the product?

Madhan45
Path Finder
  1. delivery.csv contains the fields- key,name,product,price
  2. order.csv contains the fields- key,shipdate,location,delivery_status,price
Tags (2)
0 Karma

woodcock
Esteemed Legend

You can begin a search with a pipe command, but only if that command creates events, which inputlookup does. So a search like this should work:

  | inputlookup delivery.csv | lookup order.csv key OUTPUT delivery_status | where delivery_status="failed"
0 Karma

HeinzWaescher
Motivator

Do you want to have it like this?

 | inputlookup delivery.csv
 | lookup order.csv key OUTPUT delivery_status
0 Karma

Madhan45
Path Finder

I want to find out the "name" where delivery_status is "failed".

Before this command do i need to add index=*?

can u give me a exact command?

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...