Splunk Search

Not getting results to lookup command

Nagalakshmi
Path Finder

Hi,

Need your assistance below

We have created new csv lookup and we are using the below query but we are getting  all the data from the index & sourcetype . we need to get the events only for the hosts which mentioned on the lookup is the requirement

Lookup name : Win_inventory.CSV used only one column called Server_name

index=Nagio sourcetype=nagios:core:hard 

|lookup Win_inventory.CSV Server_name as host_name OUTPUTNEW Server_name.




Server_name is not an existing interesting field

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The current query will fetch all data from the index and then lookup the Server_name field.  To fetch only the hosts in the lookup file from the index, use a subsearch.

index=Nagio sourcetype=nagios:core:hard [ | inputlookup Win_inventory.CSV | fields Server_name | rename Server_name as host_name ]
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Make sure the Nagio index contains a field called "host_name".  If it does not, then change the rename command to make the Server_name field match a field name in the index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Nagalakshmi
Path Finder

Hi @richgalloway ,

I used the above query, it is  showing 0 events 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The current query will fetch all data from the index and then lookup the Server_name field.  To fetch only the hosts in the lookup file from the index, use a subsearch.

index=Nagio sourcetype=nagios:core:hard [ | inputlookup Win_inventory.CSV | fields Server_name | rename Server_name as host_name ]
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...