Splunk Search

Is it possible to exclude search results with two lookup files?

subachu
New Member

Hi,all

I'm sorry but I use lookup for the first time.
Is it possible to exclude search results with two lookup files?

Create a host name lookup file. (HOST.csv)
Create a lookup file for the service name. (NAME.csv)

First, exclude the hostname first.

index = main source = host NOT [| inputlookup HOST.csv]

What type of search statement would you like to exclude further service names from this search result?

I thought like this.

(index = main source = host NOT [| inputlookup HOST.csv]) NOT [inputlookup NAME.csv]

Could you help me?

0 Karma

HiroshiSatoh
Champion

Try this!

 index = main source = host 
     NOT [| inputlookup HOST.csv] 
     NOT [| inputlookup NAME.csv]
↓
index=main source=host  NOT ( host=X OR host=y OR host=Z ) AND NOT (name=X OR name=y OR name=Z)
0 Karma

morethanyell
Builder

I noticed that your second inputlookup did not have a pipe. You might want to try doing 2 pipes of search such as

index=main
| search NOT [|inputlookup HOST.csv]
| search NOT [|inputlookup NAME.csv]
0 Karma

subachu
New Member

Thank you for helping me. I see. I need search command. Thank you so much!!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...