Back to Floor
The Lookup Library • Room 1

What Are Lookups?

Lookups enrich your search results by adding fields from external data sources. The most common type is a CSV lookup — a simple CSV file uploaded to Splunk.

For example, you might have a CSV that maps HTTP status codes to human-readable descriptions. A lookup lets you add a "status_description" field to every event automatically.

Other lookup types include KV Store lookups (stored in Splunk's internal database), external lookups (scripts), and geospatial lookups (for map visualizations).

Using a lookup in SPL
index=web_logs | lookup http_status_codes status OUTPUT description

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 2
What is the most common lookup type?
AKV Store
BCSV lookup
CExternal script
DGeospatial