Splunk Search

When use outputlookup, the result is output in incomplete state.

yutaka1005
Builder

Splunk ver : 6.2.7
OS : CentOS 7

I'm trying outputlookup some lookup files from one lookup file.
Below is the source lookup file.
*In fact there are more fields and values.

master.csv

host, flag
AAA, 1
BBB, 1
CCC, 1

The following is a search statement used to split and output the lookup file.

| inputlookup master.csv | search host="AAA" | outputlookup AAA.csv

| inputlookup master.csv | search host="BBB" | outputlookup BBB.csv

| inputlookup master.csv | search host="CCC" | outputlookup CCC.csv

However when I check lookup files that made by outputlookup, the value of the field flag become null!

Does anyone face such an event?
Also, if you know the solution etc, I would be pleased if you could tell me.

0 Karma

HiroshiSatoh
Champion

フィールド名が間違っているということはないですか?
例えばflagの先頭にスペースが入っているとか

0 Karma

yutaka1005
Builder

flagフィールドに関しては、元lookupファイルからそのままoutputしているので、特にフィールド名による影響は関連が無いかと思います。

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...