Splunk Search

lookup table question

shandman
Path Finder

Hello everyone.

Question:

  • I'm periodically given a .csv file provided to me from a team in my company.
  • I need to create a lookup table with the .csv file provided.
  • Need to run a search on a field in the lookup table "SESS_ID"
  • Correlate the "SESS_ID" with "IP_Address" found in the index=stream_s
  • update lookup table or provide .csv with new "IP_Address" field, extract and send back to team that provided .csv for investigation purposes

How to go about this? Making is repeatable and easy?

Thanks everyone.

0 Karma

memarshall63
Communicator

Instead of creating a lookup file from the .csv that is provided, why not just ingest the .csv file into an index? Something like this:

1) Setup a new input file monitor to watch for the provided .csv files to be added to a directory.

2) Have the other team copy any new file into that directory.
3) Splunk ingests input .csv file into new sess_id_csv index
4) Create a scheduled report that correlates the two indexes
5) Provide access to this report by the teams or have the report e-mailed back to the group that provided the .csv file.

There's always more than one way to do it. But, this is more 'self-service' for your groups.

Good luck.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...