Splunk Search

Matching value inside a lookup with wildcard?

zewashere
New Member

Hello, i'm new to Splunk and i need some advices.

I've created a lookup named my_color_lookup, with 2 column :

color,danger

red,high

yellow,medium

green,low

Then my base search is :

sourctype=foo AND customer_id=520.

This search returns me a quantity of event and has several fields. One of these fields is src_light.

I want to create a new field "risk_level" in my event

if src_light match with one color inside my lookup, i want my search to

- add a value low or medium or high in the new field risk_level

- leave the field risk_level if ther's no matching.

Thanks for your help and suggestions

Labels (1)
0 Karma

zewashere
New Member

one last things, i need to use wildcards for the search... the field src_light can have value like "dark yellow" or "deep red" and these colors need to match.

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...