<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputlookup field help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-field-help/m-p/566057#M197240</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238127"&gt;@splfedor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you tried this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_index" [ | inputlookup user_ip.csv | search client_ip="*" | table client_ip ]&lt;/LI-CODE&gt;&lt;P&gt;KV&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Sep 2021 04:35:57 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-09-07T04:35:57Z</dc:date>
    <item>
      <title>inputlookup field help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-field-help/m-p/566053#M197239</link>
      <description>&lt;P&gt;&lt;SPAN&gt;My index has client_ip.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;However, I want to use the client_ip that exists in the user_ip.csv field.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;index="my_index" [ | inputlookup user_ip.csv | search client_ip="*" ]&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Attempted but failed.&lt;BR /&gt;After that, I will perform stats.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 01:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-field-help/m-p/566053#M197239</guid>
      <dc:creator>splfedor</dc:creator>
      <dc:date>2021-09-07T01:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: inputlookup field help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/inputlookup-field-help/m-p/566057#M197240</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238127"&gt;@splfedor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you tried this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_index" [ | inputlookup user_ip.csv | search client_ip="*" | table client_ip ]&lt;/LI-CODE&gt;&lt;P&gt;KV&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 04:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/inputlookup-field-help/m-p/566057#M197240</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-09-07T04:35:57Z</dc:date>
    </item>
  </channel>
</rss>

