Splunk Search

LOOKUP table: How to add id field  name.csv file?

abi2023
Path Finder

I have two lookup table call name.csv and id.csv. both has matching field call fullname.
id.csv file has id field but name.csv doesnot. but I want to add id field to name.csv. Is anyone know how to add id field  name.csv file.
I try

| inputlookup name.csv | lookup id.csv fullname output id 

but it didnot work.

Labels (3)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @abi2023,

as @ITWhisperer said, your search should work!

did you created the Lookup Definition for the id.csv lookup? [Settings > Lookups > lookup Defintion]

which kind of issue are you reporting?

  • not all the records match,
  • no records march?

In other words, could you better describe your issue?

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like it should work. Can you provide examples of where it does not work and where it does work (if at all)?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...