Splunk Search

Lookup Tables and Comments

jchensor
Communicator

I currently am using a lookup table to match Host Names with a "grouping" category. However, there are a ton of entries in there and the order I have them in the file isn't directly obvious, so to make it easier for me to search through and edit the file, I'd love it if I could add "comments" to the lookup file. Is this possible? Can we start lines with a ':' or a '#' character or something and cause that line to be ignored during the lookup process?

Tags (3)
1 Solution

Drainy
Champion

Well its a CSV so you can't comment it.
But, you could add a comment field and simply not reference it during the lookup process? That way it will idle there un-used

UPDATE:

One way could be,

host,ip,comment
BOB,127.0.0.1,danger danger!

But you could avoid referencing the comment field completely

View solution in original post

Drainy
Champion

Well its a CSV so you can't comment it.
But, you could add a comment field and simply not reference it during the lookup process? That way it will idle there un-used

UPDATE:

One way could be,

host,ip,comment
BOB,127.0.0.1,danger danger!

But you could avoid referencing the comment field completely

Drainy
Champion

have a look at my updated answer for an example of another way to do it

0 Karma

jchensor
Communicator

Yeah, I was just thinking that a "generic" Host Name like "#comment#" that would never actually be the name of a machine could just be treated as a comment. I was hoping that maybe Splunk's lookup process would have its own construct built-in that ignored certain lines. But you're probably right in that it most likely wouldn't. ^_^

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...