Splunk Search

splunk search

SN1
Path Finder

so i have a index paloalto and a lookup file both have 1 field common app , now i want app which are present in lookup and index as well but there is a problem like in lookup if there is Alexa as an app then in index its amazon-alexa , or in lookup it is "windows xbox" in index it is "xbox-live" and some matches perfectly lilke spotify now tell me a spl where if any part of the name matches just display the app name from lookup as well as index.

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

To further @PickleRick 's recommendation, how about you tell us how that lookup is produced?  What control do you have over that production?

One way or another, you need to describe the logic to "match" index field app to lookup field app.  Why does windows xbox match xbox-live?  Does windows-xbox match xbox-unalive, too?  Why doesn't windows-xbox match mail box?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SN1 ,

you could try something like this:

index=paloalto [ | inputlookup your_lookup.csv | rename app AS query | fields query ]

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You either need to fix your lookup or make an intermediate lookup for matching one set 0f values with another. How else is your Splunk supposed to know which values match which ones? Guess? Pick at random?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...