Splunk Search

Lookup and setting default values using a variable if an entry is not found in the lookup table

sandmountain
Explorer

I have the following Query:

index=obh_prod sourcetype=obh:edge:api proxy!="ow*" |
lookup blink_six_providers ProviderId as pxrq_h_x-corapi-target-id
OUTPUT ProviderId ProviderName | fillnull value=target_id ProviderId ProviderName | dedup ProviderName ProviderId | table ProviderId ProviderName

If no values are found ProviderId, ProviderName should both get the value of pxrq_h_x-corapi-target-id.

If actually now produces:

ProviderId ProviderName

pxrq_h_x-corapi-target-idpxrq_h_x-corapi-target-idIIDP06300Valiant Bank AGIIDP00761Aargauische Kantonalbank

 

 

 

If should produce the following if the xrq_h_x-corapi-target-id e.g. contains IIDP099999 and this value is not found in the lookup. How do I get the contents of the variable and  not the name of the variable itself?

 

ProviderId ProviderName
IIDP099999IIDP099999
IIDP06300Valiant Bank AGIIDP00761Aargauische Kantonalbank

 

Labels (3)
0 Karma

sandmountain
Explorer

If should produce the following if the xrq_h_x-corapi-target-id e.g. contains IIDP099999 and this value is not found in the lookup. How do I get the contents of the variable and  not the name of the variable itself?

 

ProviderId ProviderName

IIDP099999IIDP099999
IIDP06300My Bank AG
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...