Splunk Search

Translation lookup table

Engager

I have extraction of a field called Tool (Textual)
The field values can be in English, German, French or Spanish.
I have a lookup table that contains all the options of this values in all those languages (see attached example)
alt text
I want to create a field called TranslatedTool that any event will be translated into english

0 Karma
1 Solution

Esteemed Legend

If every string everywhere is completely unique (exceedingly likely), then you can do it like this with successive lookups:

... | lookup ToolLookup English AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup French AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup German AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup Spanish AS Tool OUTPUT English AS TranslatedTool

View solution in original post

0 Karma

Esteemed Legend

If every string everywhere is completely unique (exceedingly likely), then you can do it like this with successive lookups:

... | lookup ToolLookup English AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup French AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup German AS Tool OUTPUT English AS TranslatedTool
| lookup ToolLookup Spanish AS Tool OUTPUT English AS TranslatedTool

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

If your events contain mixed languages, the easiest would be to rearrange your lookup table to have column one be all possible permutations of the values for "Tool" (including English) and have column 2 be the English translation for each (TranslatedTool).

Then you can just add a lookup command to your search or define an automatic lookup to create the field TranslatedTool with the proper English translation.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!