Splunk Search

In a CSV lookup, is the first column always the input ?

dxw350
Path Finder

In Vlookup for excel, the input is always the first column on the left. In Splunk, is this required? I am having difficulty adding the csv file with additional fields that I want to incorporate into my Splunk queries for results.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi dxw350,
what do you mean with "the input is always the first column on the left"?
In Splunk you can load a csv as a lookup or manually create a lookup using Lookup Editor App, there isn't any order or key, you can use every column as key in your searches.
You have only to create a lookup (I suggest to use Lookup Editor App) and then use it.
See at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources how to use lookups.
Bye.
Giuseppe

0 Karma

woodcock
Esteemed Legend

No, you specify the input field like this:

... | lookup YourLookupDefinition YourInputField OUTPUT Your Output Fields Here
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...