<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wildcard matching in lookup input in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708035#M239451</link>
    <description>&lt;P&gt;could you please help with SPL syntax to match wild card entry.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jan 2025 11:50:03 GMT</pubDate>
    <dc:creator>RSS_STT</dc:creator>
    <dc:date>2025-01-06T11:50:03Z</dc:date>
    <item>
      <title>wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708026#M239443</link>
      <description>&lt;P&gt;Can i do the wildcard matching in lookup?&lt;/P&gt;&lt;P&gt;|makeresults&lt;BR /&gt;|eval ip=192.168.101.10&lt;/P&gt;&lt;P&gt;|lookup ip.csv ip output host&lt;/P&gt;&lt;P&gt;In my lookup i have two entry ip=192.168.101.10 &amp;amp;&amp;nbsp;ip=192.168.101.10/24.&lt;/P&gt;&lt;P&gt;How can i add wildcard (*) for match and i should get two entry.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 10:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708026#M239443</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2025-01-06T10:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708027#M239444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in [Settings &amp;gt; Lookups &amp;gt; Lookup Definitions ] open "Advanced Options" and configure CIDR as match_type, as described at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Knowledge/Addfieldmatchingrulestoyourlookupconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Knowledge/Addfieldmatchingrulestoyourlookupconfiguration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 10:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708027#M239444</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-06T10:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708028#M239445</link>
      <description>&lt;P&gt;what if i want to match host_name= abc &amp;amp; host_name=abc_123 which is in lookup file.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 10:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708028#M239445</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2025-01-06T10:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708029#M239446</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/261968"&gt;@RSS_STT&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in the same option of the same section try with WILDCARD instead CIDR.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 10:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708029#M239446</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-06T10:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708032#M239449</link>
      <description>&lt;P&gt;The wildcard need to be defined in the lookup e.g. abc* will match abc and abc_123&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 11:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708032#M239449</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-06T11:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708035#M239451</link>
      <description>&lt;P&gt;could you please help with SPL syntax to match wild card entry.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 11:50:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708035#M239451</guid>
      <dc:creator>RSS_STT</dc:creator>
      <dc:date>2025-01-06T11:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708037#M239452</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 18:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708037#M239452</guid>
      <dc:creator>Jawahir</dc:creator>
      <dc:date>2025-01-06T18:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: wildcard matching in lookup input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708039#M239454</link>
      <description>&lt;P&gt;If you have wildcards in your lookup, just use the lookup command&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 12:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/wildcard-matching-in-lookup-input/m-p/708039#M239454</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2025-01-06T12:50:07Z</dc:date>
    </item>
  </channel>
</rss>

