<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624105#M216967</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am doing Boss of the SOC v1 and I stuck on question, where I need to use lookup. I imported .csv file ad here are my commands:&lt;/P&gt;
&lt;P&gt;index=botsv1 dest=192.168.250.70 src="23.22.63.114" http_method=POST&lt;BR /&gt;| rex field=form_data "passwd=(?&amp;lt;passwd&amp;gt;[a-zA-Z]{6})"&lt;BR /&gt;| lookup coldplay.csv Song as passwd OUTPUTNEW song&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error I get:&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Here I can find writeup with similar command:&amp;nbsp;&lt;A href="https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?" target="_blank" rel="noopener"&gt;https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;I tried to run it and I received the same error.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Do you know how can I solve it?&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 13 Dec 2022 15:16:18 GMT</pubDate>
    <dc:creator>suspense</dc:creator>
    <dc:date>2022-12-13T15:16:18Z</dc:date>
    <item>
      <title>BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624105#M216967</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am doing Boss of the SOC v1 and I stuck on question, where I need to use lookup. I imported .csv file ad here are my commands:&lt;/P&gt;
&lt;P&gt;index=botsv1 dest=192.168.250.70 src="23.22.63.114" http_method=POST&lt;BR /&gt;| rex field=form_data "passwd=(?&amp;lt;passwd&amp;gt;[a-zA-Z]{6})"&lt;BR /&gt;| lookup coldplay.csv Song as passwd OUTPUTNEW song&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error I get:&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Here I can find writeup with similar command:&amp;nbsp;&lt;A href="https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?" target="_blank" rel="noopener"&gt;https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;I tried to run it and I received the same error.&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;Do you know how can I solve it?&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Dec 2022 15:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624105#M216967</guid>
      <dc:creator>suspense</dc:creator>
      <dc:date>2022-12-13T15:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624112#M216970</link>
      <description>&lt;P&gt;That's because your coldplay.csv file doesn't contain a field named &lt;FONT face="andale mono,times"&gt;song&lt;/FONT&gt;. &amp;nbsp;OUTPUT or OUTPUTNEW can only take what is found in the lookup. &amp;nbsp;If your lookup contains a field name &lt;FONT face="andale mono,times"&gt;poem&lt;/FONT&gt; and you want to rename it &lt;FONT face="andale mono,times"&gt;song&lt;/FONT&gt;, you have to reference &lt;FONT face="andale mono,times"&gt;poem&lt;/FONT&gt; first, like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| lookup coldplay.csv Song AS passwd OUTPUTNEW poem AS song&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 13 Dec 2022 10:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624112#M216970</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-13T10:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624116#M216971</link>
      <description>&lt;P&gt;This is how my .csv looks like. How can I find which fields I have? I thought name of the column is considered a field?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cold.PNG" style="width: 662px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22986i1F5A754665043AED/image-size/large?v=v2&amp;amp;px=999" role="button" title="cold.PNG" alt="cold.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 10:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624116#M216971</guid>
      <dc:creator>suspense</dc:creator>
      <dc:date>2022-12-13T10:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624118#M216973</link>
      <description>&lt;P&gt;Yes, the field name is &lt;U&gt;S&lt;/U&gt;ong, not &lt;U&gt;s&lt;/U&gt;ong. &amp;nbsp;Also, if the lookup only contains one field, what do you expect to look up? &amp;nbsp;The purpose of a lookup is to associate a known field value in search result to one or more field values that are only known in the lookup.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 10:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624118#M216973</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-13T10:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624119#M216974</link>
      <description>&lt;P&gt;I am trying to do BotS and answer on question:&lt;/P&gt;&lt;P&gt;One of the passwords in the brute force attack is James Brodsky’s favorite Coldplay song. Which six character song is it?&lt;/P&gt;&lt;P&gt;Basically I am trying to import list of Coldplay songs in .csv and compare it with password used for brute force attack.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the answer how the query should look like (probably?):&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?" target="_blank"&gt;https://www.aldeid.com/wiki/TryHackMe-BP-Splunk/Advanced-Persitent-Threat##7_-_One_of_the_passwords_in_the_brute_force_attack_is_James_Brodsky%E2%80%99s_favorite_Coldplay_song._Which_six_character_song_is_it?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index=botsv1 sourcetype=stream:http form_data=*username*passwd*
| rex field=form_data "passwd=(?&amp;lt;userpassword&amp;gt;\w+)"
| eval lenpword=len(userpassword)
| search lenpword=6
| eval password=lower(userpassword)
| lookup coldplay.csv song as password OUTPUTNEW song
| search song=*
| table song&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 10:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624119#M216974</guid>
      <dc:creator>suspense</dc:creator>
      <dc:date>2022-12-13T10:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: BotS - Error in 'lookup' command: Could not find all of the specified destination fields in the lookup table.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624124#M216977</link>
      <description>&lt;P&gt;BTW. If you look at this website -theirs syntax with lookup and list that they attached in a link - this syntax just cannot work. I tested in my lab and it does not work. But you helped me to understand that last 'song' must be 'Song' &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 11:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/BotS-Error-in-lookup-command-Could-not-find-all-of-the-specified/m-p/624124#M216977</guid>
      <dc:creator>suspense</dc:creator>
      <dc:date>2022-12-13T11:47:41Z</dc:date>
    </item>
  </channel>
</rss>

