Splunk Search

Search Input based on a inputlookup

aquinojason
Path Finder

Hi, 

I am trying to do the following:

1. Using this | inputlookup Application.csv where BusinessUnit = BU1, it will filter a list of Account Codes e.g. AC1, AC2, AC3

2. I want to use that list of Account Codes to filter my search on a different sourcetype.

index=index1 sourcetype=sourctypeN ACCOUNT_CODE = "AC1" or ACCOUNT_CODE "AC2" and so on..

Thanks!

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Put the two searches together like this:

index=index1 sourcetype=sourctypeN [ | inputlookup Application.csv where BusinessUnit = BU1 | return 1000 ACCOUNT_CODE ]
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Put the two searches together like this:

index=index1 sourcetype=sourctypeN [ | inputlookup Application.csv where BusinessUnit = BU1 | return 1000 ACCOUNT_CODE ]
---
If this reply helps you, Karma would be appreciated.
0 Karma

aquinojason
Path Finder
Spoiler
Thank you. it worked.
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...