Splunk Search

New to field lookup help me !

sbnoobbb
Path Finder

Hi Splunk professionals, I am new to field lookup and read the documentation about it. But I am still not sure how can I implement it with my data.

I have the weather data of many locations and example of my data is displayed below. How can I use a field lookup to check if summary is cloudy, fishing is Good, else if summary is Rain, fishing is Poor. How can I start with field lookup ? Any advises ?

Area: Woodlands
Summary: Rain
Latitude: 1.44043052
Longitude: 103.7878418

I would like to do something like this.

1 Solution

Ayn
Legend

If that's the only thing you'd want to do I'd go with eval and case instead. That said, this is core lookup functionality - lookup one value, output another - so I'm not sure what the docs aren't explaining.

View solution in original post

AlexMcDuffMille
Communicator

I was having a hard time getting it to work, then eventaully I realized that I had a few commas in some of my fields that I was looking up. Once I got rid of those and made sure my table was good it worked well.

0 Karma

Ayn
Legend

If that's the only thing you'd want to do I'd go with eval and case instead. That said, this is core lookup functionality - lookup one value, output another - so I'm not sure what the docs aren't explaining.

sbnoobbb
Path Finder

Thanks ! I am not very sure about case (will study it tmr), but can it do like what the picture in the updated question ? Will look at it tmr morning, need to get to bed.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...