Splunk Search

inclusion of .csv file in search


I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then iterate line-by-line through the entries in said file, much like a subsearch would work. While I suspect I could do this with a python script of some kind, is there any way to do this in 4.x? The use case scenario in this case could be iterating through a very long list of domain names.


Tags (1)


It looks like this answer works out a bit better:


Splunk Employee
Splunk Employee

There are a few ways you can input files as search terms.

inputcsv and inputlookup

http://www.splunk.com/base/Documentation/latest/SearchReference/Inputcsv http://www.splunk.com/base/Documentation/latest/SearchReference/Inputlookup

Both of the above commands should allow you to input a csv or similar data.


The Inputcsv bit doesn't quite do what I was looking for, unless I am confused about its operation.

0 Karma