Splunk Search

Lookup full text of Cisco event and display in new window?


I have a search time field extraction for CISCO system messages named MsgClassID. I uploaded from Manager a CISCOevt_codes.csv table. Given that the table format looks like this:

   101001,(Primary) Failover cable OK,1,alert

I would like to do a discretionary lookup from the MsgClassID field pulldown and using the value of MsgClassID against error_code, I would like to return the full discription for the event in a new window.

Haven't been able to find any examples ... Is it possible to do ?

0 Karma

Splunk Employee
Splunk Employee

Sure. That sounds like you want a basic "workflow action" (what used to be simply called "field action"):


0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...