How to create and manipulate Splunk Lookup | Configuring Time Based Lookup | Basic & Adv. query

Опубликовано: 17 Июль 2026
на канале: CyberSatrix
1,883
54

Hello Everyone! In this video I have explained Splunk CSV based lookup in detail and covered various concepts and queries. It will be useful for beginner and advanced level professional. Splunk lookup are used to enrich the event data.
Please find the below topics covered in this video

00:43 Agenda
01:45 Lookup Overview
03:31 Lookup - Search time operation sequence
04:48 Overview - Lookup table files, Lookup definition and Automatic Lookup
07:38 Sample data & understanding enrichment of data
09:18 Hands On - creation of CSV based lookup
14:53 Hands On - Inputlookup command
15:56 Hand On - Creation of Lookup Definition
17:51 Hand On -Applying Lookup command and corresponding Keywords (OUTPUT/OUTPUT NEW)
25:30 Hand On - Creation of Automatic Lookup
31:14 Hand On - Applying Outputlookup command
35:05 Hand On - Advanced Query using Bluecoat (Proxy logs) to identify user connecting to malicious IP Address
43:42 Configuring Time Based Lookup

***** WATCH OUT FOR BELOW SECTION FOR LINKS MENTIONED IN THE SESSION *****
Splunk Doc - About Lookups
https://docs.splunk.com/Documentation...
Splunk DOC - Define a CSV lookup in Splunk Web
https://docs.splunk.com/Documentation...
Splunk DOC- Search Time Operation Sequence
https://docs.splunk.com/Documentation...
Download the Sample Data (tutorialdata.zip and Prices.csv.zip)
http://docs.splunk.com/Documentation/...
Bluecoat Sample DataSet
http://log-sharing.dreamhosters.com/b...

********** WATCH THIS SECTION FOR MY OTHER VIDEOS ***********

1. Launching AWS instance in AWS Console -    • AWS : How to Launch a Linux Instance  
2. Terraform Introduction and Installation -    • Launching AWS Instance using Terraform - P...  
3. Terraform code to set up basic infrastructure in AWS provider -    • Launching AWS Instance using Terraform - P...  
4. Terraform code to access the Instance using different methods -    • Launching AWS Instance using Terraform - P...  
5. SIEM SPLUNK | GuardDuty | AWS GuardDuty Integration with Splunk via AWS S3 Bucket -
   • SIEM SPLUNK | GuardDuty | AWS GuardDuty In...  
6. SPLUNK | SQS | EVENT BRIDGE | GuardDuty | Amazon SQS Queue to Onboard GuardDuty Findings to Splunk
   • SPLUNK | SQS | EVENT BRIDGE | GuardDuty | ...