Splunk Search

REST command is not including all columns from CSV

Mary666
Communicator

Hello Splunk Community 

I have managed to use REST to add some columns from my CSV files. However, not all the columns are uploaded. I am using the below script: 

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather.Lookups.csv"

But the issue is that I am not getting all the fields associated with *_Weather.Lookups.csv anybody out there  know how I can het all the fields or a specific field from the lookup ? Thanks in advance. 

Labels (2)
Tags (1)
0 Karma
1 Solution

Mary666
Communicator

I was able to figure it out, so basically:

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather_Report.csv"| inputlookup  append=t New_Jersey_Weather_Report.csv 


I just needed to add the append=t to have the lookup show me everything in it while still having the rest command. 

View solution in original post

0 Karma

Mary666
Communicator

I was able to figure it out, so basically:

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather_Report.csv"| inputlookup  append=t New_Jersey_Weather_Report.csv 


I just needed to add the append=t to have the lookup show me everything in it while still having the rest command. 

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...