<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: spl query in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675677#M113065</link>
    <description>&lt;P&gt;Please share some anonymised sample events to show what you are working with&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jan 2024 14:33:09 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-01-28T14:33:09Z</dc:date>
    <item>
      <title>Filter using a lookup.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675674#M113064</link>
      <description>&lt;P&gt;I want to write a query whose purpose is to print for users who are not authorized to enter, and of course with the presence of a lookup table, the people who are authorized to enter are present in it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 11:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675674#M113064</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-29T11:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: spl query</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675677#M113065</link>
      <description>&lt;P&gt;Please share some anonymised sample events to show what you are working with&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 14:33:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675677#M113065</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-28T14:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: spl query</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675701#M113071</link>
      <description>&lt;P&gt;index="(index name)" sourcetype=source type (host="host1" OR host="host2")&lt;BR /&gt;| search NOT [| inputlookup (lookup table name ) | table username] action=success | stats values(username) as user&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 06:14:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675701#M113071</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-29T06:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: spl query</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675733#M113076</link>
      <description>&lt;P&gt;OK it looks like it should work - what is your question?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 09:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675733#M113076</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-29T09:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: spl query</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675737#M113078</link>
      <description>&lt;P&gt;It does not retrieve the blacklist, but rather it retrieves some of the whitelist. I want to make it pass through the lookuptable and show the user who is not authorized to enter.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 09:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675737#M113078</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-29T09:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: spl query</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675738#M113079</link>
      <description>&lt;P&gt;The principle of what you are doing is correct. So, if it is not working, it may come down to the actually data, which understandably you might not want to share. How are the values which are getting through different to the ones which are being removed? How large is your lookup table? Are there any special characters being used?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 09:57:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-using-a-lookup/m-p/675738#M113079</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-29T09:57:51Z</dc:date>
    </item>
  </channel>
</rss>

