<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754118#M242827</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you could try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=paloalto [ | inputlookup your_lookup.csv | rename app AS query | fields query ]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2025 06:32:04 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2025-10-09T06:32:04Z</dc:date>
    <item>
      <title>splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754116#M242825</link>
      <description>&lt;P&gt;so i have a index paloalto and a lookup file both have 1 field common app , now i want app which are present in lookup and index as well but there is a problem like in lookup if there is Alexa as an app then in index its amazon-alexa , or in lookup it is "windows xbox" in index it is "xbox-live" and some matches perfectly lilke spotify now tell me a spl where if any part of the name matches just display the app name from lookup as well as index.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 05:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754116#M242825</guid>
      <dc:creator>SN1</dc:creator>
      <dc:date>2025-10-09T05:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754117#M242826</link>
      <description>&lt;P&gt;You either need to fix your lookup or make an intermediate lookup for matching one set 0f values with another. How else is your Splunk supposed to know which values match which ones? Guess? Pick at random?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 06:02:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754117#M242826</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-09T06:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754118#M242827</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you could try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=paloalto [ | inputlookup your_lookup.csv | rename app AS query | fields query ]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 06:32:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754118#M242827</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-10-09T06:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754131#M242828</link>
      <description>&lt;P&gt;To further&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;'s recommendation, how about you tell us how that lookup is produced? &amp;nbsp;What control do you have over that production?&lt;/P&gt;&lt;P&gt;One way or another, you need to describe the logic to "match" index field &lt;FONT face="courier new,courier"&gt;app&lt;/FONT&gt; to lookup field &lt;FONT face="courier new,courier"&gt;app&lt;/FONT&gt;. &amp;nbsp;Why does &lt;U&gt;windows xbox&lt;/U&gt; match &lt;U&gt;xbox-live&lt;/U&gt;? &amp;nbsp;Does &lt;U&gt;windows-xbox&lt;/U&gt; match &lt;U&gt;xbox-unalive&lt;/U&gt;, too? &amp;nbsp;Why doesn't &lt;U&gt;windows-xbox&lt;/U&gt; match &lt;U&gt;mail box&lt;/U&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 14:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search/m-p/754131#M242828</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2025-10-09T14:50:05Z</dc:date>
    </item>
  </channel>
</rss>

