Splunk Search

lookup table question

shandman
Path Finder

Hello everyone.

Question:

  • I'm periodically given a .csv file provided to me from a team in my company.
  • I need to create a lookup table with the .csv file provided.
  • Need to run a search on a field in the lookup table "SESS_ID"
  • Correlate the "SESS_ID" with "IP_Address" found in the index=stream_s
  • update lookup table or provide .csv with new "IP_Address" field, extract and send back to team that provided .csv for investigation purposes

How to go about this? Making is repeatable and easy?

Thanks everyone.

0 Karma

memarshall63
Communicator

Instead of creating a lookup file from the .csv that is provided, why not just ingest the .csv file into an index? Something like this:

1) Setup a new input file monitor to watch for the provided .csv files to be added to a directory.

2) Have the other team copy any new file into that directory.
3) Splunk ingests input .csv file into new sess_id_csv index
4) Create a scheduled report that correlates the two indexes
5) Provide access to this report by the teams or have the report e-mailed back to the group that provided the .csv file.

There's always more than one way to do it. But, this is more 'self-service' for your groups.

Good luck.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...