Dear Splunk community,
I'm new to Splunk, so excuse my incompetence...
What I'm trying to do is enriching my web access log with app name and team name from a csv lookup file.
The CSV file "ingress_map.csv" looks like this:
ingress,app,team
https://mycompany.com/abc,foo-bar,a-team
https://app.mycompany.com,good-app,b-team
https://app.mycompany.com/abc,better-app,c-team
https://app.mycompany.com/abc/xyz,best-app,d-team
The url field of my web access log will seldom match exactly one of the ingresses, is it possible to have a lookup that finds the best matching ingress and adds the fields app and team to the log line? Or is there a better way of solving this problem?
Regards
Terje Gravvold
... View more