Splunk Search

Lookup full text of Cisco event and display in new window?


I have a search time field extraction for CISCO system messages named MsgClassID. I uploaded from Manager a CISCOevt_codes.csv table. Given that the table format looks like this:

   101001,(Primary) Failover cable OK,1,alert

I would like to do a discretionary lookup from the MsgClassID field pulldown and using the value of MsgClassID against error_code, I would like to return the full discription for the event in a new window.

Haven't been able to find any examples ... Is it possible to do ?

0 Karma

Splunk Employee
Splunk Employee

Sure. That sounds like you want a basic "workflow action" (what used to be simply called "field action"):


0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!