Splunk Search

Splunk query - lookup utilization

KishoreSrini
Explorer

Hello all, 

I am working on an Splunk query which suppose to filter some logs by utilizing data from lookup. Consider a field called host. I have list of host stored on an lookup (let's call the lookup as hostList.csv). Now, I want to retrieve the list of servers from the hostList.csv lookup. And then filter the field host with the retrieved set of list. 

Note - I don't want use map command for this. 

If is there any other way of pull off this logic. Please help me with example query and explanation. 

Thank you!

0 Karma
1 Solution

KishoreSrini
Explorer

Hi @ITWhisperer , 

Thank your help. 

With your suggestion, I also included a format command to format the output with "OR," which is now working.

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format]


Once again, Thank you for the help @ITWhisperer .

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=* [| inputlookup hostList.csv | table host ]

KishoreSrini
Explorer

Hi @ITWhisperer , 

I have tried this method. The host name on the log is structured like "hostname.abcgroup.com". I want to search like, "hostname*". Since, the hostnames are retrieved from lookup it's working as a static string search. Not filtering the host. I tried like this after get the data from lookup,

| eval host_pattern=host."*"
| table host_pattern

But, this is also not working. I guess the Splunk may consider the wildcard * as string. Since, I am filtering like this. Any suggestion for this...

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format ]

KishoreSrini
Explorer

Hi @ITWhisperer , 

Thank your help. 

With your suggestion, I also included a format command to format the output with "OR," which is now working.

index=* [| inputlookup hostList.csv | eval string="host=".host."*" | table string | format]


Once again, Thank you for the help @ITWhisperer .

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I have updated my response (I couldn't remember if the default was to format with "OR" or not!)

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...