Splunk Search

Trying to match a field with multiple values against a lookuptable

marktechuk
New Member

I trying to search a lookup table for matching field=user the field contains multiple values for example
user=ID, name, email, address - so when I run the search it only match on email the first value in field user against my lookuptable test1.csv

I there a way for my to split out the values of field user into multiple fields that I can match against my lookuptable.

index=** sourcetype=** event=** | table user | dedup user | lookup test1.csv user outputnew user as matchEvent

0 Karma
1 Solution
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...