Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Lookup File Issues

$
0
0
Hello I have multiple Questions about Lookup Files. 1. Can you upload a lookup file into Splunk and search fields in the lookup file such that it returns values in those fields without having to correlate the result with any other search? If yes what is the syntax to do that? I tried typing | inputlookup UCMDB.csv | table Server_Name in Splunk but it isn't returning any values. 2. I have a search string I have developed and displayed beautifully how I want it i.e. I have used the stats and table command to display it nicely. This result displays a field say Host_Name that contains the names of servers and host of other fields. I have a lookup file with a field called Server_name and a corresponding field called Owners. How do I pipe my beautifully displayed search string into the lookup table so it searches the Host_Name field against the Server_name field and adds the Owners field to the display against each server that is found in the lookup table? 3. Just to clarify should I be able to search against the lookup file just by uploading it to Splunk in the lookup table manager? I want to confirm it works hence the question 1 so when I am troubleshooting question 2 I know the issue is not the lookup table rather my search string or something else. Thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>