Splunk Search

Can you add dynamically to your events when theres a match in lookup?

ashishlal82
Explorer

I have a static or .csv file that lookups with a field in the events. If there is a match It should create a field dynamically and assign a certain value ( 0 or 1) , without using automatic lookup and adding a field in .csv field.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You've got a solution in your question already - add an output field to your lookup, and define an automatic lookup on your data.

If for some reason you cannot change the .csv file as it comes in, you could define a scheduled search that periodically reads the immutable .csv via inputlookup, adds the output field via eval, and writes that to a second .csv via outputlookup. That second .csv gets used in the automatic lookup.
Is there any other reason why you don't want to use the obvious solution you already found?

Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...