Splunk Search

How to use search a CSV lookup file within an App via Python SDK?

BrentRiva
Explorer

I'm working in Python and trying to use the SDK to search from a program. One of the apps I have installed uses a lookup table (CSV file) to add fields to events, and I'm trying to search on those events (specifically, the CSV file in the app adds 'cost_center=____' to the data, and I'm trying to search for a specific call center).

As I don't know how to do this, my searches right now are returning 0 results. Is there a place I can read up on this, or is the answer easy enough to answer here?

Edit: Would namespace=<app_name> work?
Thanks!

0 Karma

BrentRiva
Explorer

Namespace= seems to be working, but I'm getting much less results than normal, though (1 million on the website vs. 260 on the API call). I think this is the answer, but I'll wait until a more definitive answer is posted.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...