Splunk Search

Possible To Insert Your Own Values?

henryt1
Path Finder

I was curious if it is possible to insert your own values into a chart/table? For instance if I had a search that returned five different host names in a column and in the next column it had a number that represented something. Could I manually create a third column and insert values that I need? If so what would the script look like to do this? Thanks in advance!

Tags (3)
0 Karma

MHibbin
Influencer

Hi henryt1,

I think you should look at lookups...

http://docs.splunk.com/Documentation/Splunk/latest/knowledge/Addfieldsfromexternaldatasources

If you're information is fairly static and can be stored in a csv file you should look here (this file obviously can be updated by a script if the need is required, but that's another story)...

http://docs.splunk.com/Documentation/Splunk/latest/User/CreateAndConfigureFieldLookups

Regards,

MHibbin

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...