In Vlookup for excel, the input is always the first column on the left. In Splunk, is this required? I am having difficulty adding the csv file with additional fields that I want to incorporate into my Splunk queries for results.
Hi dxw350,
what do you mean with "the input is always the first column on the left"?
In Splunk you can load a csv as a lookup or manually create a lookup using Lookup Editor App, there isn't any order or key, you can use every column as key in your searches.
You have only to create a lookup (I suggest to use Lookup Editor App) and then use it.
See at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources how to use lookups.
Bye.
Giuseppe
No, you specify the input field like this:
... | lookup YourLookupDefinition YourInputField OUTPUT Your Output Fields Here