Splunk Search

Read CSV and use with index info

nsantiago17
Explorer

(first four rows)
JOB_NAME,Description
ATUALIZACAOATIVOS,BATCH-PRO-AGRO
BLOQUEIO-EMISSORES,BATCH-PRO-AGRO
CONCATENAPDF,BATCH-PRO-AGRO
FINALIZACAODATAD0,BATCH-PRO-AGRO

I have a csv file above and I'm trying to extract the JOB_NAME value and use on the query :

index=darth sourcetype=vader
| lookup sla2.csv JOB_NAME as JOB_NAME OUTPUT Descriptions as Descriptions
| stats values(JOB_NAME) as Job, values(START_TIME) as ST by Descriptions

The START_TIME data is coming from the index

I'm receiving the following error: "Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table." What can I do to fix it and run my search? Ps: I have to use fake names bc I'm dealing with classified data.

0 Karma
1 Solution

woodcock
Esteemed Legend

The field name Description does not have an s; try this:

index=darth sourcetype=vader 
| lookup sla2.csv JOB_NAME as JOB_NAME
| stats values(JOB_NAME) AS Job, values(START_TIME) AS ST BY Description

View solution in original post

0 Karma

woodcock
Esteemed Legend

The field name Description does not have an s; try this:

index=darth sourcetype=vader 
| lookup sla2.csv JOB_NAME as JOB_NAME
| stats values(JOB_NAME) AS Job, values(START_TIME) AS ST BY Description
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Field names specified in the lookup command must match exactly those in the header of the CSV file. In your example, "Descriptions" does not match "Description". Perhaps that was an error in writing the question, but it's often the cause of that error message.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...