I'm a fairly inexperienced Splunk user that could use some pointers on how to accomplish building a dashboard/table using a lookup table — any advice or guidance is appreciated.
I have a fairly simple lookup table (userlist.csv) of a list of users of this format:
username_1,fullname_1
username_2,fullname_2
username_3,fullname_3
etc.
Basically I want a table with this info:
username_1,fullname_1,workstation_name_1,ip_addr_1
username_2,fullname_2,workstation_name_2,ip_addr_2
username_3,fullname_3,workstation_name_3,ip_addr_3
I can generate a table of that format using a search like this:
| inputlookup userlist.csv | table username,fullname,workstation_name,ip_addr
But of course those last two fields are blank in the table. I have searches for the workstation_name (which is based on the username) and the ip_addr (which is based on the workstation_name) but not sure how to tie these into the resulting table so that this info will populate the table.
... View more