Getting Data In

How can I filter data in search-time from a generated csv file?

skender27
Contributor

Hi,

I have a csv file, generated each day from a Powershell script under the Splunk app lookups directory.
I use the info in those records with the | inputlookup command in many other searches. The columns are name, surname and domain of the internal company network.

Is there a way to filter (in search time) only some of those records present in the .csv file (maybe in a wildcard fashion - for example: eliminate those which name start with adm*)?

Thanks for any suggestion,
Skender

0 Karma
1 Solution

adayton20
Contributor

If I understand your request, is this sort of what you're looking for?

|inputlookup testlookup1 | search NOT user=adm*

or for just the user field

|inputlookup testlookup1 | fields + user | search NOT user=adm*

(whatever your field is)

alt text

alt text

View solution in original post

adayton20
Contributor

If I understand your request, is this sort of what you're looking for?

|inputlookup testlookup1 | search NOT user=adm*

or for just the user field

|inputlookup testlookup1 | fields + user | search NOT user=adm*

(whatever your field is)

alt text

alt text

woodcock
Esteemed Legend

The inputlookup command is no different than using index=myindex sourcetype=mysourcetype; you have all the same filtering options with additional pipelines of commands. The only difference is that you must do a | search first. So you can do something like this:

| inputlookup | search NOT name="adm*"
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...