Splunk Search

Using value in lookup as source in search

eoghanmcd
Engager

Hello,

I am new to Splunk so apologies if this question seems overly simple.

Currently I have a search where in the query I list off the different sources, e.g.

 index=my_index host=my_host (source=".../component_1.log" OR source=".../component_2.log" OR ... etc)  "keyword"

However, requirements have changed and I now need to store that list of sources in a lookup file, which looks like this

source,
".../component_1.log"
".../component_2.log"
...
".../component_n.log"

Can I take the values stored in the lookup file and use them as a the source value in a subsequent search? It seems like something very easy but I just can't seem to get it right.

I have added the lookup correctly to my splunk environment and can see its contents okay.

|inputlookup my_lookup.csv

I just can't seem to combine the two elements, am I missing something basic?

|inputlookup my_lookup.csv | rename source as lookup_source | fields lookup_source | search index=my_index host=my_host source=lookup_source "keyword"

Thanks.

0 Karma
1 Solution

to4kawa
Ultra Champion
index=my_index host=my_host  "keyword" [|inputlookup my_lookup.csv ]

View solution in original post

to4kawa
Ultra Champion
index=my_index host=my_host  "keyword" [|inputlookup my_lookup.csv ]
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...