Splunk Search

lookup with _row

oda
Communicator

Can I use _row when matching with lookup?
It seems to me that it can not be done.
Can you give me some hints?

0 Karma
1 Solution

HiroshiSatoh
Champion

If you search keywords

ex)
index=XXX [|inputlookup XXX.csv|table key_value|rename key_value as query]

Look at this
https://answers.splunk.com/answers/7472/subsearch-fields-query-search-how-do-i-know-which-to-use.htm...

View solution in original post

0 Karma

HiroshiSatoh
Champion

If you search keywords

ex)
index=XXX [|inputlookup XXX.csv|table key_value|rename key_value as query]

Look at this
https://answers.splunk.com/answers/7472/subsearch-fields-query-search-how-do-i-know-which-to-use.htm...

0 Karma

harsmarvania57
Ultra Champion

Why you want to match _raw data with lookup ? Can't you use any field value to match data with lookup ? If your fields values are not exactly matching with lookup table data then you can implement wildcard lookup.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...