Splunk Search

Using lookup tables

jbouch03
Path Finder

Having trouble getting a lookup table to replace my results. I have a lookup file that contains the following info:

AET,Location
FakeAET,Fakeplace

I have loaded the .csv file, and I have created a file-based lookup definition called AETtolocation. When I run my search I want to replace the results of the AET column with the info in the Location column, but everytime I run it I only get the information inside the AET column. Here is my searchstring:

eventtype="calling" | chart count by calling | lookup AETtolocation AET OUTPUT Location

Any assistance you could provide would be greatly appreciated. Thank you in advance.

Tags (2)
1 Solution

Ayn
Legend

The lookup command is doing precisely what it's told to do. The stuff before OUTPUT is which fields you want to use as input to your lookup and the stuff after OUTPUT is which fields should be output. In your case the lookup will read the value of the field "AET" in your event, try to match it to its "AET" values and if it finds a match, it will write the matching value in the "Location" field in your event.

If you want to output to another field you can do it like this:

... | lookup AETtolocation AET OUTPUT Location AS AET

More info in the docs: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup

View solution in original post

Ayn
Legend

The lookup command is doing precisely what it's told to do. The stuff before OUTPUT is which fields you want to use as input to your lookup and the stuff after OUTPUT is which fields should be output. In your case the lookup will read the value of the field "AET" in your event, try to match it to its "AET" values and if it finds a match, it will write the matching value in the "Location" field in your event.

If you want to output to another field you can do it like this:

... | lookup AETtolocation AET OUTPUT Location AS AET

More info in the docs: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup

jbouch03
Path Finder

I got it...It was extra spacing in my results. I fixed the spacing in my transform and it went perfectly. thanks again.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...