Splunk Search

Issue in csv lookup while summarization

keerthana_k
Communicator

Hi,

We have scheduled saved search running every 5 minutes to create summary index.

In our test setup we get 200 log events every 5 minutes. The log events contain ServerIP field. We do a CSV lookup to get meaningful name for the server IP.

Our summarization query looks like this:

First part of the query | stats …… by _time, ServerIP, ….| lookup for ServerName | other fields.

When we verified the data in summarized index, there are some null values for the ServerName field. For the same ServerIP the lookup is successful at times and failing at other times.

Additional Information:

The CSV file has 50 entries
The IP addresses for which we do lookup are in positions 24 and 30.

Tags (2)
0 Karma
1 Solution

keerthana_k
Communicator

The problem was that the CSV file was up to date in one indexer and not updated in the other one. Hence the lookup was failing half the time.

View solution in original post

0 Karma

keerthana_k
Communicator

The problem was that the CSV file was up to date in one indexer and not updated in the other one. Hence the lookup was failing half the time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...