Splunk Search

How to load a list of values for a search from the GUI

larrywest
Explorer

How can I look for a list of 50+ values without typing in "foo=1 OR foo=29 OR foo=4219...".

Obviously without touching files on /opt/splunk/ anything, but as a normal file user.

I would like to load this from a file on my machine, a command something like inputcsv or inputlookup which, if I understand correctly, are restricted to looking on the Splunk server.

Tags (2)
0 Karma

lguinn2
Legend

It is true that inputlookup and inputcsv use files on the Splunk server. However, power users can upload files into Splunk using the lookup capability, and therefore use these commands. You don't have to be a Splunk admin.

0 Karma

larrywest
Explorer

SPLUNK: I can't edit my own question, just submitted moments ago, because the edit Captcha is broken. Tried 10+ times, most not difficult. Safari 7.0.3 on a Mac.

I would have changed the middle to say "without touching any files on /opt/splunk, but as a normal user"/

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...