Splunk Search

REST command is not including all columns from CSV

Mary666
Communicator

Hello Splunk Community 

I have managed to use REST to add some columns from my CSV files. However, not all the columns are uploaded. I am using the below script: 

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather.Lookups.csv"

But the issue is that I am not getting all the fields associated with *_Weather.Lookups.csv anybody out there  know how I can het all the fields or a specific field from the lookup ? Thanks in advance. 

Labels (2)
Tags (1)
0 Karma
1 Solution

Mary666
Communicator

I was able to figure it out, so basically:

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather_Report.csv"| inputlookup  append=t New_Jersey_Weather_Report.csv 


I just needed to add the append=t to have the lookup show me everything in it while still having the rest command. 

View solution in original post

0 Karma

Mary666
Communicator

I was able to figure it out, so basically:

| rest /servicesNS/-/-/data/lookup-table-files search="*_Weather_Report.csv"| inputlookup  append=t New_Jersey_Weather_Report.csv 


I just needed to add the append=t to have the lookup show me everything in it while still having the rest command. 

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...