<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: refining search after lookup command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62730#M15491</link>
    <description>&lt;P&gt;After lookup, add &lt;CODE&gt;| search client_country="germany"&lt;/CODE&gt;. Just that easy!&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2013 01:59:58 GMT</pubDate>
    <dc:creator>sowings</dc:creator>
    <dc:date>2013-09-13T01:59:58Z</dc:date>
    <item>
      <title>refining search after lookup command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62729#M15490</link>
      <description>&lt;P&gt;Forgive me if this has been asked before, but I am trying to do a lookup using geoip (maxmind database) to resolve IP's to countries, which works great. This is what I have so far&lt;/P&gt;

&lt;P&gt;sourcetype="fsisac-2" | lookup geoip clientip as IP &lt;/P&gt;

&lt;P&gt;In my field list I now have a "client_country" field. I now want to add "client_country=germany" to the query, but whether I add this at the end, or before the Pipe. How do I construct the query to now only show me IP's that are coming from Germany?&lt;/P&gt;

&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62729#M15490</guid>
      <dc:creator>gjohnson</dc:creator>
      <dc:date>2020-09-28T14:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: refining search after lookup command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62730#M15491</link>
      <description>&lt;P&gt;After lookup, add &lt;CODE&gt;| search client_country="germany"&lt;/CODE&gt;. Just that easy!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2013 01:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62730#M15491</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-09-13T01:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: refining search after lookup command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62731#M15492</link>
      <description>&lt;P&gt;That is exactly it! I would not have thought to have add the word "search" back onto the search bar - probably just late at night for me. Thanks again!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2013 02:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62731#M15492</guid>
      <dc:creator>gjohnson</dc:creator>
      <dc:date>2013-09-13T02:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: refining search after lookup command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62732#M15493</link>
      <description>&lt;P&gt;Excellent. If that worked for you, consider clicking the checkmark next to the response, so that others can know that it's a working solution. Happy Splunking!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2013 03:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/refining-search-after-lookup-command/m-p/62732#M15493</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-09-13T03:06:33Z</dc:date>
    </item>
  </channel>
</rss>

