Splunk Search

output lookup search correlation with input lookup data

brdr
Contributor

Hello, can you use a output lookup table just after creating it? I have this search...

index=indexA sourcetype=mystA | table src | outputlookup new.csv
| search index=indexB sourcetype=mystB [| inputlookup new.csv | rename src as src_ip ]
| table user
| lookup user.csv AS user OUTPUT displayName

When I run this I get no data found, however, when I separate out the outputlookup command and the subsearch and run I get results as expected.

0 Karma

brdr
Contributor

reposted initially as an Answer: reposting as a comment:

My use case is:
I need a count of users by there business units. To do this I do:
output list IPs as seen in blue coat logs
index=indexA sourcetype=mystA | table src | outputlookup new.csv
using this list (new.csv) match on IP to get user name from our authentication data (indexB) to display business unit
| search index=indexB sourcetype=mystB [| inputlookup new.csv | table src | rename src as src_ip ]
| table user
| lookup user.csv uname as user OUTPUT displayName businessUnit
| stats count by businessUnit

0 Karma

brdr
Contributor

My use case is:

I need a count of users by there business units. To do this I do:

  • output list IPs as seen in blue coat logs
    index=indexA sourcetype=mystA | table src | outputlookup new.csv

  • using this list (new.csv) match on IP to get user name from our authentication data (indexB) to display business unit
    | search index=indexB sourcetype=mystB [| inputlookup new.csv | table src | rename src as src_ip ]
    | table user
    | lookup user.csv uname as user OUTPUT displayName businessUnit
    | stats count by businessUnit

0 Karma

somesoni2
Revered Legend

I don't think you can do that. What's your use case here?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...