Splunk Search

How to write a search to join the data from four lookups on a unique field?

cadence_asif
Observer

Hello Experts,

Can you please help me with a search to join these four lookups on login (unique field). Lookups LOOKUP_A.CSV, LOOKUP_B.CSV, LOOKUP_C.CSV need to be joined to MASTER_lookup to form a RESULT_LOOKUP.

Appreciate your help with this.

Please check the source lookups and resultingdesired lookup. (attachment/inline image)

alt text

0 Karma

subtrakt
Contributor

Another option?

| inputlookup  MASTER_LOOKUP.CSV | inputlookup LOOKUP_A.CSV append=t | inputlookup LOOKUP_B.CSV  append=t | inputlookup LOOKUP_C.CSV  append=t | outputlookup RESULT_LOOKUP.csv
0 Karma

javiergn
Super Champion

What about this?

| inputcsv MASTER_LOOKUP.csv
| join type=left login [| inputcsv LOOKUP_A.csv]
| join type=left login [| inputcsv LOOKUP_B.csv]
| join type=left login [| inputcsv LOOKUP_C.csv]
| outputcsv RESULT_LOOKUP.csv
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...