Splunk Search

Matching value inside a lookup with wildcard?

zewashere
New Member

Hello, i'm new to Splunk and i need some advices.

I've created a lookup named my_color_lookup, with 2 column :

color,danger

red,high

yellow,medium

green,low

Then my base search is :

sourctype=foo AND customer_id=520.

This search returns me a quantity of event and has several fields. One of these fields is src_light.

I want to create a new field "risk_level" in my event

if src_light match with one color inside my lookup, i want my search to

- add a value low or medium or high in the new field risk_level, 

- leave the field risk_level if ther's no matching.

Thanks for your help and suggestions

Labels (1)
0 Karma

zewashere
New Member

one last things, i need to use wildcards for the search... the field src_light can have value like "dark yellow" or "deep red" and these colors need to match.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...