Splunk Search
Highlighted

I want to pick up values from different columns from lookup files according to the sourcetype.

New Member

I want to pick up values from different lookup files according to the sourcetype.
| lookup errorrules.csv EventSubType Criticality OUTPUT waittime thresholdcount windowlimit

Say i have two source type 1 and type2

For type1 i want to lookup EventSubType and Criticalitytype1 in lookup errorrules.csv
For type2 i want to lookup EventSubType and Criticalitytype2 in lookup errorrules.csv

Please suggest the solution for this scenario if case needs to be used let me know how it will be implemented.

Tags (2)
0 Karma
Highlighted

Re: I want to pick up values from different columns from lookup files according to the sourcetype.

SplunkTrust
SplunkTrust

not sure i fully understand, but how about something along those lines:

 ... your search ... (sourcetype=1 OR sourcetype=2) ... | lookup error_rules.csv EventSubType Criticality OUTPUT wait_time threshold_count window_limit
| eval Criticality_type1= if(sourcetype=="1",Criticality,null())
| eval Criticality_type2= if(sourcetype=="2",Criticality,null())
| .... more stuff if you want 
0 Karma
Highlighted

Re: I want to pick up values from different columns from lookup files according to the sourcetype.

Esteemed Legend

Just add sourcetype to your lookup file.

0 Karma
Highlighted

Re: I want to pick up values from different columns from lookup files according to the sourcetype.

Esteemed Legend

Like this:

... | eval Criticality = if(sourceype="type1", Criticality_type1, Criticality_type2)
| lookup error_rules.csv EventSubType Criticality OUTPUT wait_time threshold_count window_limit
| fields - Criticality
0 Karma