Hello,I have a csv file ,and I use it as a lookup table, it has two fields : IP,IP Name;
| inputlookup ip_name.csv
and my data has source_ip, the source_ip corresponds to the IP in csv file.
I want to show a table such as : source_ip,IP Name
how do I write the SPL?
@WXY,
"your search to get source_ip" |lookup ip_name.csv IP AS source_ip
Reference : http://docs.splunk.com/Documentation/Splunk/7.2.0/SearchReference/Lookup
Run anywhere example:
|makeresults |eval ISO="Austria"|lookup geo_attr_countries.csv country as ISO