Splunk Search
Highlighted

adding data from lookup to search

Path Finder

I have a spreadsheet.csv with the following info:
date, SID
16/03/2016, x555xx5x5
...

I want to add the SID value as Account_Name to search:

index=blah source=blah.log Account_Name= |stats count

Whats the most efficient method and example in distributed environment?

Thanks in advance!

0 Karma
Highlighted

Re: adding data from lookup to search

SplunkTrust
SplunkTrust

Try something like this (based on where you've your csv file, choose between inputcsv( if in $SPLUNKHOME/var/run/splunk) or inputlookup (if it's added as lookup table file $SPLUNKHOME/etc/apps/AppName/lookups)

index=blah source=*blah.log [inputcsv spreadsheet.csv | stats count by SID | table SID | rename SID as Account_Name] |stats count
Highlighted

Re: adding data from lookup to search

Path Finder

cool thanks!

0 Karma