Splunk Search

Splunk query - lookup utilization

KishoreSrini
Explorer

Hello all, 

I am working on an Splunk query which suppose to filter some logs by utilizing data from lookup. Consider a field called host. I have list of host stored on an lookup (let's call the lookup as hostList.csv). Now, I want to retrieve the list of servers from the hostList.csv lookup. And then filter the field host with the retrieved set of list. 

Note - I don't want use map command for this. 

If is there any other way of pull off this logic. Please help me with example query and explanation. 

Thank you!

0 Karma
1 Solution

KishoreSrini
Explorer

Hi @ITWhisperer , 

Thank your help. 

With your suggestion, I also included a format command to format the output with "OR," which is now working.

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format]


Once again, Thank you for the help @ITWhisperer .

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=* [| inputlookup hostList.csv | table host ]

KishoreSrini
Explorer

Hi @ITWhisperer , 

I have tried this method. The host name on the log is structured like "hostname.abcgroup.com". I want to search like, "hostname*". Since, the hostnames are retrieved from lookup it's working as a static string search. Not filtering the host. I tried like this after get the data from lookup,

| eval host_pattern=host."*"
| table host_pattern

But, this is also not working. I guess the Splunk may consider the wildcard * as string. Since, I am filtering like this. Any suggestion for this...

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format ]

KishoreSrini
Explorer

Hi @ITWhisperer , 

Thank your help. 

With your suggestion, I also included a format command to format the output with "OR," which is now working.

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format]


Once again, Thank you for the help @ITWhisperer .

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I have updated my response (I couldn't remember if the default was to format with "OR" or not!)

Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...