Splunk Search

Is it possible to exclude search results with two lookup files?

subachu
New Member

Hi,all

I'm sorry but I use lookup for the first time.
Is it possible to exclude search results with two lookup files?

Create a host name lookup file. (HOST.csv)
Create a lookup file for the service name. (NAME.csv)

First, exclude the hostname first.

index = main source = host NOT [| inputlookup HOST.csv]

What type of search statement would you like to exclude further service names from this search result?

I thought like this.

(index = main source = host NOT [| inputlookup HOST.csv]) NOT [inputlookup NAME.csv]

Could you help me?

0 Karma

HiroshiSatoh
Champion

Try this!

 index = main source = host 
     NOT [| inputlookup HOST.csv] 
     NOT [| inputlookup NAME.csv]
↓
index=main source=host  NOT ( host=X OR host=y OR host=Z ) AND NOT (name=X OR name=y OR name=Z)
0 Karma

morethanyell
Builder

I noticed that your second inputlookup did not have a pipe. You might want to try doing 2 pipes of search such as

index=main
| search NOT [|inputlookup HOST.csv]
| search NOT [|inputlookup NAME.csv]
0 Karma

subachu
New Member

Thank you for helping me. I see. I need search command. Thank you so much!!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...