Splunk Search

Not getting results to lookup command

Nagalakshmi
Path Finder

Hi,

Need your assistance below

We have created new csv lookup and we are using the below query but we are getting  all the data from the index & sourcetype . we need to get the events only for the hosts which mentioned on the lookup is the requirement

Lookup name : Win_inventory.CSV used only one column called Server_name

index=Nagio sourcetype=nagios:core:hard 

|lookup Win_inventory.CSV Server_name as host_name OUTPUTNEW Server_name.




Server_name is not an existing interesting field

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The current query will fetch all data from the index and then lookup the Server_name field.  To fetch only the hosts in the lookup file from the index, use a subsearch.

index=Nagio sourcetype=nagios:core:hard [ | inputlookup Win_inventory.CSV | fields Server_name | rename Server_name as host_name ]
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Make sure the Nagio index contains a field called "host_name".  If it does not, then change the rename command to make the Server_name field match a field name in the index.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Nagalakshmi
Path Finder

Hi @richgalloway ,

I used the above query, it is  showing 0 events 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The current query will fetch all data from the index and then lookup the Server_name field.  To fetch only the hosts in the lookup file from the index, use a subsearch.

index=Nagio sourcetype=nagios:core:hard [ | inputlookup Win_inventory.CSV | fields Server_name | rename Server_name as host_name ]
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...