Splunk Tutorial: Lookup

# Create a csv file

colname1,colname2
<val1>,<val1> has been converted
<val2>,<val2> has been converted

index=_internal*
--------
log_level,colname2
INFO,INFO has been converted
WARN,WARN has been converted
-----
add this csv file to lookup table
& Give all Permission
---

index=_internal* log_level=* | lookup test.csv log_level OUTPUT colname2 | table log_level colname2 
index=_internal* log_level=* | lookup lookup.csv log_level OUTPUT colname2 | table log_level colname2 
Rajesh Kumar
Follow me
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x