data:image/s3,"s3://crabby-images/bb26f/bb26f520e8e696e119b11934757569a829e121f1" alt="Splunk inputlookup"
data:image/s3,"s3://crabby-images/df0ab/df0abbef6a48638cb23d0dd00c5824b1c0659da0" alt="splunk inputlookup splunk inputlookup"
| where ( >= info_min_time AND <= info_max_time) If you HAVE included a time field in your lookup then you can also use 's solution above: Once you have a time field, you can re-map it to the _time field, which should allow you to use search (you don't need latest=now(), Splunk assumes that if you don't provide a latest= statement).
#Splunk inputlookup update#
You would need some logic that executes when you update / create your lookup to add a time value that equates to the execution time of the creation / update of the lookup. Even if it DOES reference a time value, it may not be the time value you are thinking of. To find the shopper who accessed the online shop the most, use this search. Use the top command to return the most frequent shopper. This means that the owner also defines which fields to include in the lookup, which may or may not (most do not) have a field that references a time value. Example 1: Search without a subsearch You want to find the single most frequent shopper on the Buttercup Games online store and what that shopper has purchased.
data:image/s3,"s3://crabby-images/241d1/241d1f5dae01df7df903d7c919a79d6929e11b48" alt="splunk inputlookup splunk inputlookup"
One possible search is: sourcetypemail lookup searchip ip OUTPUT. You are now ready to use your file as input to search for all events that contain ip addresses that were in your CSV file.
data:image/s3,"s3://crabby-images/491b8/491b8593334c3a77471ff0e2902aeb76af38f538" alt="splunk inputlookup splunk inputlookup"
Lookup files are basically state tables that the owner defines and updates. Now, from your browser, log into Splunk and reload the nf and nf file for your new additions: sourcetypemail extract reloadtrue. If you have not included a time value anywhere in your lookup, then you cannot do this.
data:image/s3,"s3://crabby-images/bb26f/bb26f520e8e696e119b11934757569a829e121f1" alt="Splunk inputlookup"