Splunk Search

lookup table question

shandman
Path Finder

Hello everyone.

Question:

  • I'm periodically given a .csv file provided to me from a team in my company.
  • I need to create a lookup table with the .csv file provided.
  • Need to run a search on a field in the lookup table "SESS_ID"
  • Correlate the "SESS_ID" with "IP_Address" found in the index=stream_s
  • update lookup table or provide .csv with new "IP_Address" field, extract and send back to team that provided .csv for investigation purposes

How to go about this? Making is repeatable and easy?

Thanks everyone.

0 Karma

memarshall63
Communicator

Instead of creating a lookup file from the .csv that is provided, why not just ingest the .csv file into an index? Something like this:

1) Setup a new input file monitor to watch for the provided .csv files to be added to a directory.

2) Have the other team copy any new file into that directory.
3) Splunk ingests input .csv file into new sess_id_csv index
4) Create a scheduled report that correlates the two indexes
5) Provide access to this report by the teams or have the report e-mailed back to the group that provided the .csv file.

There's always more than one way to do it. But, this is more 'self-service' for your groups.

Good luck.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...