Splunk Search

Lookup Table

mailmetoramu
Explorer

Hello All,

Actually i have an lookup table DIUSERS.csv, i would like to build a query as like below :

index=* |inputlookup DIUSERS.csv|stats count by src dest user name action index

But its not working, Please let me know the correct queries.

 

Thanks.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What problem are you trying to solve with the lookup file?  Debugging a query is difficult without knowing the goal.

Have you read the Search Reference manual to see the differences between inputlookup and lookup?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...