Splunk Search

Lookup against an Array

gbam
Explorer

I'm trying to run a lookup against a list of values in an array.  I have a CSV which look as follows:

idxy
123DataData2
321DataData2
456Data3Data3

 

The field from the search is is an array which looks as follows:

["123", "321", 456"]

I want to map the lookup value.  Do I need to iterate over the field or can I use a lookup or is the best option?

Labels (4)
0 Karma

tscroggins
Champion

Hi @gbam,

Splunk provides an eval function, json_array_to_mv, to convert JSON-like array values to multivalued field values. After conversion, you can use the lookup command just as you would for any other field:

| makeresults
| eval id="[\"123\", \"321\", \"456\"]"
| eval id=json_array_to_mv(id, false())
| lookup gbam_lookup.csv id
_time id x y
2023-11-10 16:14:53 123
321
456
Data
Data
Data3
Data2
Data2
Data3

 

Index 0 of multivalued field id corresponds to index 0 of multivalued fields x and y, index 1 corresponds to index 1, etc.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...