Splunk Search

Lookup matching field and bring in new field from lookup

rpatelnes
New Member

Hello, I've been banging my head against the wall over the last like two hours over this and figured I should just post since I don't find Splunk documentation that helpful, detailed, or plentiful.

Objective: What I want to do is we have the results from a nice search query. Now we want to take the full hostname and compare that to a field in the Lookup and from there bringing in an related alternate field from that lookup.

The example hopefully is easy to understand and something quick I'm just screwing up.
alt text

So our query below is returning us the following:
alt text

What I want to accomplish is use the CSV lookup file I have, use the clienthost field and compare that against the DNS field in my lookup file. And from there automatically pull in the matching related value from Description. Does that make sense hopefully. I tried every variation of using | | lookup ComputerNameDescription.csv DNS as clienthost OUTPUT Description, etc. Idk. I tried like 20 different ways and it's not looking it up, matching and letting me bring in the matching Description.

Can someone please tell me what we're doing wrong.

Thanks

0 Karma

rpatelnes
New Member

No real answer yet, all suggestions have failed so far.

0 Karma

rpatelnes
New Member

@kamlesh_vaghela

I have tried that as one of the variations when I was going through the documentation, but it still doesn't work. See my image below:
alt text

@jkat54

Yes there is a match. I'm matching the DNS field in the CSV to my clienthost field in my events which should align. See images.

Any further ideas?

0 Karma

jkat54
SplunkTrust
SplunkTrust

Not in your search sample you gave.

You need to give lookup command more details.

See the lookup command documentation Kamlesh provided.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Try swapping clienthost and DNS around

0 Karma

jkat54
SplunkTrust
SplunkTrust

I don’t see the ip fields in your lookup.

So there’s nothing to match/join it to.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@rpatelnes

Have you tried OUTPUTNEW option of lookup command ?

Can you please confirm DescriptionNew returning anything using below lookup command?

| lookup ComputerNameDescription.csv DNS as clienthost OUTPUTNEW Description as DescriptionNew

Ref:
https://docs.splunk.com/Documentation/SplunkCloud/7.1.3/SearchReference/Lookup

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...