Splunk Search

Splunk inputlookup comparison and rex

sbondred
Explorer

I have 2 lookup files as

  1. lookup1.csv and
  2. lookup2.csv

lookup1.csv has the data as below

name, designation, server, ipaddress, dept
tim, ceo, hostname.com, 1.2.3.5, alldept
jim, vp, myhost.com, 1.0.3.5, marketing
pim, staff, nohost.com, 4.0.4.8, hr

lookup2.csv has the data as below

cidr, location
1.2.3.0/24, dc
1.0.3.0/24, carolina
3.4.7.0/24, tx

I would like to lookup for the field ipaddress in lookup1.csv with the field cidr in lookup2.csv for the first 3 digits as in x.x.x and get the location field if they match. If the ipaddress doesn't match the first 3 digit of cidr , the location should be marked as "unknown".

Expected o/p

tim, ceo,1.2.4.5, dc
jim, vp, 1.0.3.5, carolina
pim, staff, 4.0.4.8, unkown

I am looking for the search command in splunk using the 2 lookup tables. Thanks in advance. My search so far has not yield any good results but I am still working on it.

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @sbondred,

you have to configure your second lookup to match cidr:

  • go in [Settings > Lookup Definitions]
  • flag on Advanced options
  • put CIDR in the Match Type option
  • save

and the run a simple search like the following:

| inputlookup lookup1.csv
| lookup lookup2.csv cidr AS ipaddress OUTPUT location
| table name designation server ipaddress dept location

 Ciao.

Giuseppe

View solution in original post

sbondred
Explorer

Actually, it was my lookuptable name I was using wrong. Its working. Thanks again @gcusello

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sbondred ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sbondred,

you have to configure your second lookup to match cidr:

  • go in [Settings > Lookup Definitions]
  • flag on Advanced options
  • put CIDR in the Match Type option
  • save

and the run a simple search like the following:

| inputlookup lookup1.csv
| lookup lookup2.csv cidr AS ipaddress OUTPUT location
| table name designation server ipaddress dept location

 Ciao.

Giuseppe

sbondred
Explorer

Thanks @gcusello

I setup the lookup definition to match type as CIDR(cidr) as that is the field name in the file and used the same search as mentioned below. For some reason, it does't provide me the location. It seems like it is not able to lookup for some reason. Still troubleshooting.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...