Splunk Search

Read CSV and use with index info

nsantiago17
Explorer

(first four rows)
JOB_NAME,Description
ATUALIZACAOATIVOS,BATCH-PRO-AGRO
BLOQUEIO-EMISSORES,BATCH-PRO-AGRO
CONCATENAPDF,BATCH-PRO-AGRO
FINALIZACAODATAD0,BATCH-PRO-AGRO

I have a csv file above and I'm trying to extract the JOB_NAME value and use on the query :

index=darth sourcetype=vader
| lookup sla2.csv JOB_NAME as JOB_NAME OUTPUT Descriptions as Descriptions
| stats values(JOB_NAME) as Job, values(START_TIME) as ST by Descriptions

The START_TIME data is coming from the index

I'm receiving the following error: "Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table." What can I do to fix it and run my search? Ps: I have to use fake names bc I'm dealing with classified data.

0 Karma
1 Solution

woodcock
Esteemed Legend

The field name Description does not have an s; try this:

index=darth sourcetype=vader 
| lookup sla2.csv JOB_NAME as JOB_NAME
| stats values(JOB_NAME) AS Job, values(START_TIME) AS ST BY Description

View solution in original post

0 Karma

woodcock
Esteemed Legend

The field name Description does not have an s; try this:

index=darth sourcetype=vader 
| lookup sla2.csv JOB_NAME as JOB_NAME
| stats values(JOB_NAME) AS Job, values(START_TIME) AS ST BY Description
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Field names specified in the lookup command must match exactly those in the header of the CSV file. In your example, "Descriptions" does not match "Description". Perhaps that was an error in writing the question, but it's often the cause of that error message.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...