Splunk Search

Lookup values not shown on result table

dunick
Engager

Hello all,

I am searching in Splunk for the last login date of a User and export it into a table:

... | eval date=strftime(_time,"%F")
| stats latest(date) by U
| table U, latest(date)

Now I have a lookup table (user_info.csv) containing ALL UserID from the system.
I would like to include all of them on the my search results, even those who never logged-in in the system. For example (PWMDN):

UserID  Last login
 JLSME  2019-02-21
KOEMN   2019-10-12
PWMDN   Never (or 1900-01-01)
JDEMI   2019-09-11

Do you have any Idea how to do it?
Thank you very much

0 Karma

cmerriman
Super Champion

i would append the lookup table with the user_info.csv

Something similar to

<base search to gather all active users with latest login date>
|rename U as UserID
|inputlookup user_info.csv append=true
|stats latest(last_login) as last_login by UserID
|fillnull last_login value="Never"

dunick
Engager

Thank you very much, it works!!

0 Karma

woodcock
Esteemed Legend

Come back and click Accept to close the question.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...