<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Look up table with &amp;amp;quot;*&amp;amp;quot; or &amp;amp;quot;any&amp;amp;quot; field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636488#M221045</link>
    <description>&lt;P&gt;Will match_type WILDCARD help? &amp;nbsp;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Create_a_CSV_lookup_definition" target="_blank" rel="noopener"&gt;Create a CSV lookup definition&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2023 09:02:08 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2023-03-29T09:02:08Z</dc:date>
    <item>
      <title>How to create a look up table with "*&amp;" or "any" field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636469#M221038</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I am trying to whitelist some traffic from my search. So I decided to create a look up table including src ip, dst ip, username, dst port, src zone.&lt;/P&gt;
&lt;P&gt;for example:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;src_ip&lt;/TD&gt;
&lt;TD width="135.516px"&gt;dest_ip&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;src_zone&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;dest_port&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;user&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;whitelisted&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;*&lt;/TD&gt;
&lt;TD width="135.516px"&gt;*&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;center&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;172.16.20.44&lt;/TD&gt;
&lt;TD width="135.516px"&gt;13.58.90.11&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;443&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;Alice&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;*&lt;/TD&gt;
&lt;TD width="135.516px"&gt;128.221.236.246&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;443&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;192.168.12.03&lt;/TD&gt;
&lt;TD width="135.516px"&gt;*&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;172.16.20.13&lt;/TD&gt;
&lt;TD width="135.516px"&gt;*&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;192.168.26.4&lt;/TD&gt;
&lt;TD width="135.516px"&gt;*&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;192.168.26.8&lt;/TD&gt;
&lt;TD width="135.516px"&gt;198.160.25.74&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;443&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;192.168.26.9&lt;/TD&gt;
&lt;TD width="135.516px"&gt;198.160.25.87&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;*&lt;/TD&gt;
&lt;TD width="135.516px"&gt;142.250.70.174&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="116.312px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="135.516px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="77.3594px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="82.8594px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="46.5469px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="90.5781px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but the problem is the search matches when all cells related to fields which are called in lookup command have values, but it does not match (does not whitelist) if a cell has "*" or "Any"&amp;nbsp; value.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;| lookup whitelisttest.csv src_ip as src_ip dest_ip as dest_ip dest_port as dest_port user as user&lt;BR /&gt;| where isnull(whitelisted)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 15:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636469#M221038</guid>
      <dc:creator>Erfan</dc:creator>
      <dc:date>2023-03-29T15:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636488#M221045</link>
      <description>&lt;P&gt;Will match_type WILDCARD help? &amp;nbsp;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usefieldlookupstoaddinformationtoyourevents#Create_a_CSV_lookup_definition" target="_blank" rel="noopener"&gt;Create a CSV lookup definition&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 09:02:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636488#M221045</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-29T09:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636604#M221088</link>
      <description>&lt;P&gt;Thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a look up definition and in match type I entered:&amp;nbsp; WILDCARD(dest_ip)&lt;/P&gt;&lt;P&gt;I expected to see all result except traffic from 172.16.20.13:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="116.312px"&gt;172.16.20.13&lt;/TD&gt;&lt;TD width="135.516px"&gt;*&lt;/TD&gt;&lt;TD width="77.3594px"&gt;*&lt;/TD&gt;&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but it did not showed any records. I mean it remove all result not only whitelisted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 23:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636604#M221088</guid>
      <dc:creator>Erfan</dc:creator>
      <dc:date>2023-03-29T23:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636649#M221104</link>
      <description>&lt;P&gt;You need to give more details about your data with illustration, including an explanation of key characteristics, and illustrate the desired results.&lt;/P&gt;&lt;P&gt;If every event contains these four fields,&amp;nbsp;src_ip, dest_ip, dest_port, and user, your lookup&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| lookup whitelisttest.csv src_ip dest_ip dest_port user ``` no need to use "as" annotator if the name is the same ```​&lt;/LI-CODE&gt;&lt;P&gt;will always return whitelisted "TRUE". &amp;nbsp;This is because &lt;SPAN&gt;in addition to the row you just quoted, you also have this row&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="116.312px"&gt;src_ip&lt;/TD&gt;&lt;TD width="135.516px"&gt;dest_ip&lt;/TD&gt;&lt;TD width="77.3594px"&gt;src_zone&lt;/TD&gt;&lt;TD width="82.8594px"&gt;dest_port&lt;/TD&gt;&lt;TD width="46.5469px"&gt;user&lt;/TD&gt;&lt;TD width="90.5781px"&gt;whitelisted&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="116.312px"&gt;*&lt;/TD&gt;&lt;TD width="135.516px"&gt;*&lt;/TD&gt;&lt;TD width="77.3594px"&gt;center&lt;/TD&gt;&lt;TD width="82.8594px"&gt;*&lt;/TD&gt;&lt;TD width="46.5469px"&gt;*&lt;/TD&gt;&lt;TD width="90.5781px"&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;In other words, the whild card search is working exactly as you asked.&lt;/P&gt;&lt;P&gt;In fact, I suggested wildcard only because you entered "*" in the table. &amp;nbsp;Splunk's lookup also supports CIDR match. &amp;nbsp;This is probably more appropriate for IP address filtering. &amp;nbsp;Just food for thought.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 07:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636649#M221104</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-30T07:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636811#M221144</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;SPAN&gt;Yuanliu&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;let me rephrase my question, maybe lookup is not a good solution for my problem.&lt;/P&gt;&lt;P&gt;Actually I want to whitelist following traffic on search of fortigate's logs:&lt;/P&gt;&lt;P&gt;Traffic from 172.16.20.12 to every where&lt;/P&gt;&lt;P&gt;traffic from 192.168.26.8 to 198.160.25.74&lt;/P&gt;&lt;P&gt;traffic from every where to 142.250.70.174&lt;/P&gt;&lt;P&gt;traffic from any to any related to a specific user (Alice)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All records include all fields.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 04:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636811#M221144</guid>
      <dc:creator>Erfan</dc:creator>
      <dc:date>2023-03-31T04:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636820#M221150</link>
      <description>&lt;P&gt;Suitability is always defined by the data and requirements. &amp;nbsp;In the case you described, you can still use lookup to establish the desired whitelist. &amp;nbsp;For example, if you use match_type WILDCARD in every field, you can say&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="116.296875px" height="25px"&gt;src_ip&lt;/TD&gt;&lt;TD width="135.515625px" height="25px"&gt;dest_ip&lt;/TD&gt;&lt;TD width="77.359375px" height="25px"&gt;src_zone&lt;/TD&gt;&lt;TD width="82.859375px" height="25px"&gt;dest_port&lt;/TD&gt;&lt;TD width="46.546875px" height="25px"&gt;user&lt;/TD&gt;&lt;TD width="90.578125px" height="25px"&gt;whitelisted&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="116.296875px" height="25px"&gt;&lt;SPAN&gt;172.16.20.12&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="135.515625px" height="25px"&gt;*&lt;/TD&gt;&lt;TD width="77.359375px" height="25px"&gt;center&lt;/TD&gt;&lt;TD width="82.859375px" height="25px"&gt;*&lt;/TD&gt;&lt;TD width="46.546875px" height="25px"&gt;*&lt;/TD&gt;&lt;TD width="90.578125px" height="25px"&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;192.168.26.8&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;198.160.25.74&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;142.250.70.174&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;Alice&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;and use the same search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| lookup whitelisttest.csv src_ip dest_ip dest_port user
| where isnull(whitelisted)&lt;/LI-CODE&gt;&lt;P&gt;Now, if you want future ability to use CIDR for more granular control, set src_ip and dest_ip to use CIDR, and change lookup to&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="116.296875px" height="25px"&gt;src_ip&lt;/TD&gt;&lt;TD width="135.515625px" height="25px"&gt;dest_ip&lt;/TD&gt;&lt;TD width="77.359375px" height="25px"&gt;src_zone&lt;/TD&gt;&lt;TD width="82.859375px" height="25px"&gt;dest_port&lt;/TD&gt;&lt;TD width="46.546875px" height="25px"&gt;user&lt;/TD&gt;&lt;TD width="90.578125px" height="25px"&gt;whitelisted&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="116.296875px" height="25px"&gt;&lt;SPAN&gt;172.16.20.12/32&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="135.515625px" height="25px"&gt;0.0.0.0/0&lt;/TD&gt;&lt;TD width="77.359375px" height="25px"&gt;center&lt;/TD&gt;&lt;TD width="82.859375px" height="25px"&gt;*&lt;/TD&gt;&lt;TD width="46.546875px" height="25px"&gt;*&lt;/TD&gt;&lt;TD width="90.578125px" height="25px"&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;192.168.26.8/32&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;198.160.25.74/32&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;0.0.0.0/0&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;142.250.70.174/32&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;0.0.0.0/0&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;0.0.0.0/0&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;center&lt;/TD&gt;&lt;TD&gt;*&lt;/TD&gt;&lt;TD&gt;Alice&lt;/TD&gt;&lt;TD&gt;TRUE&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 06:25:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/636820#M221150</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-31T06:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/638276#M221227</link>
      <description>&lt;P&gt;Thank you so much.&lt;/P&gt;&lt;P&gt;The only vague part for me is that how to create match type for wildcard on all fields in GUI version.&lt;/P&gt;&lt;P&gt;I think this works for CUI:&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;field1,field2,field3,output_field,match_type &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;value1,value2,value3,output_value,*&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But I do not have acccess to CUI and it is just GUI. So I defined WILDCARD(*) but did not work.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 00:01:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/638276#M221227</guid>
      <dc:creator>Erfan</dc:creator>
      <dc:date>2023-04-03T00:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Look up table with &amp;quot;*&amp;quot; or &amp;quot;any&amp;quot; field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/638402#M221256</link>
      <description>&lt;P&gt;You can add as many wildcard lookup fields as needed. This is the instruction from Splunk Web (GUI)&lt;/P&gt;&lt;BLOCKQUOTE&gt;Optionally set up non-exact matching of a comma-and-space-delimited field list. Format is &amp;lt;match_type&amp;gt;(&amp;lt;field_name&amp;gt;). Available values for match_type are WILDCARD and CIDR.&lt;/BLOCKQUOTE&gt;&lt;P&gt;No need for CUI.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 15:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-create-a-look-up-table-with-quot-amp-quot-or-quot-any/m-p/638402#M221256</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-04-03T15:11:49Z</dc:date>
    </item>
  </channel>
</rss>

