Splunk Search

LOOKUP table: How to add id field  name.csv file?

abi2023
Path Finder

I have two lookup table call name.csv and id.csv. both has matching field call fullname.
id.csv file has id field but name.csv doesnot. but I want to add id field to name.csv. Is anyone know how to add id field  name.csv file.
I try

| inputlookup name.csv | lookup id.csv fullname output id 

but it didnot work.

Labels (3)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @abi2023,

as @ITWhisperer said, your search should work!

did you created the Lookup Definition for the id.csv lookup? [Settings > Lookups > lookup Defintion]

which kind of issue are you reporting?

  • not all the records match,
  • no records march?

In other words, could you better describe your issue?

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like it should work. Can you provide examples of where it does not work and where it does work (if at all)?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...