Splunk Search

How to write a search to join the data from four lookups on a unique field?

cadence_asif
Observer

Hello Experts,

Can you please help me with a search to join these four lookups on login (unique field). Lookups LOOKUP_A.CSV, LOOKUP_B.CSV, LOOKUP_C.CSV need to be joined to MASTER_lookup to form a RESULT_LOOKUP.

Appreciate your help with this.

Please check the source lookups and resultingdesired lookup. (attachment/inline image)

alt text

0 Karma

subtrakt
Contributor

Another option?

| inputlookup  MASTER_LOOKUP.CSV | inputlookup LOOKUP_A.CSV append=t | inputlookup LOOKUP_B.CSV  append=t | inputlookup LOOKUP_C.CSV  append=t | outputlookup RESULT_LOOKUP.csv
0 Karma

javiergn
SplunkTrust
SplunkTrust

What about this?

| inputcsv MASTER_LOOKUP.csv
| join type=left login [| inputcsv LOOKUP_A.csv]
| join type=left login [| inputcsv LOOKUP_B.csv]
| join type=left login [| inputcsv LOOKUP_C.csv]
| outputcsv RESULT_LOOKUP.csv
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...