Splunk Search

Possible To Insert Your Own Values?

henryt1
Path Finder

I was curious if it is possible to insert your own values into a chart/table? For instance if I had a search that returned five different host names in a column and in the next column it had a number that represented something. Could I manually create a third column and insert values that I need? If so what would the script look like to do this? Thanks in advance!

Tags (3)
0 Karma

MHibbin
Influencer

Hi henryt1,

I think you should look at lookups...

http://docs.splunk.com/Documentation/Splunk/latest/knowledge/Addfieldsfromexternaldatasources

If you're information is fairly static and can be stored in a csv file you should look here (this file obviously can be updated by a script if the need is required, but that's another story)...

http://docs.splunk.com/Documentation/Splunk/latest/User/CreateAndConfigureFieldLookups

Regards,

MHibbin

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...