Splunk Search

Appending Lookup Match to Search Results

driva
Path Finder

Hi all,

I have a search that filters results based on a lookup file. Is there a simple way that I can add the match from the lookup file to the table/results?

index=web[| inputlookup HighRiskWords.csv | eval HighRiskWords="*"+HighRiskWords+"*" | rename HighRiskWords as web_Search] | stats count by web_Search, web_User, _time

It would be great to have the final piece of the search to be: Web_Search, {web_MatchingLookup}, web_user, _time

Thanks!

0 Karma

13tsavage
Communicator

Can you elaborate and provide more details to what exactly you are trying to do?

0 Karma

starcher
Influencer

don't do that. use a lookup as a lookup and make it a wildcard match type.

index=web 
| lookup HighRiskWords web_Search outputnew web_Search as isFound
| where isnotnull(isFound)
| stats count by web_Search, web_User, _time
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...