Hi, Under lookups we have lookups as below lookups abcd.csv xyz.csv I could see configs in props.conf to map to these lookups props.conf LOOKUP-field1-field2 = abcd_lookup field OUTPUTNEW f...
Hi, In lookup definition, IT_server_list is created in lookup definition which is mapped to CSV named (server_list.csv) In Lookup Table, server_list.csv file is there In automatic lookup, I...
Hello Splunkers,
Please if someone can help me with a Splunk query,
I have a list of IPs I imported in lookup table, I want to grab the FW traffic where dest_ip in the FW logs matches my lookup l...
Hi at all, In Enterprise Security, I'm trying to customize a Suppression Rule inserting a lookup containing the ip addresses to whitelist in one Correlation Search, using this search: &n...
I am looking for some tool/way to get the Splunk index/lookup usage in the system
for example to get all lookups that are not used in the system
what is the best way to do it ?
...ombination from the results.
The following query allows for excluding source_ip from the lookup table. How would I be able to exclude source_ip and destination_ip combination?
index=f...
The scenario is,
A lookup csv has become unreadable. A lookup definition exists for it.
The lookup was deleted and recreated. The existing definition was not changed.
My q...
I am trying to match results to ONLY the names in a list I have using a lookup. I cant figure out for the life of me what I am doing wrong, been trying every single variated on lookup and i...
Hello everyone,
I got several fields in search result (name, ip_src). Now I have lookup with 2 columns:
name
subnet
name1
10.10.10.1/24
name2
10.20.10.1/2...
Is something like this possible?
index=main sourcetype=iis
host IN (| inputlookup serverlistA.csv)
I think the problem may be that inputlookup is a generatin...