Splunk Search

Lookup command can take wildcard(*) as an input.

vranjith009
New Member

Suppose i have a lookup with two fields input and output.

Initial,Final
abc*,abc
def*,def

so anything matches with abc* should give abc as output. Similarly anything matches with def* should give def as output.

Added csv file in lookups file of particular app.
Created transforms.conf in local folder and added below lines.
[abc]
filename = abc.csv

I m not getting anything with the below query.

index=* sourcetype=* | lookup abc Initial OUTPUT Final

Thanks in advance

Tags (1)
0 Karma

vranjith009
New Member

Thanks Michaelis... got the answer

0 Karma

JMichaelis
Path Finder
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...