Since I don't see much documentation for this app, what needs to be set in order for the lookups to happen? Do I need to change sourcetype, source?
The main thing is to make sure your sourcetype is set to ias
.
Not sure I follow. Are you expecting to see a difference in the log entries themselves? The lookup values appear as new extracted fields, so you should start to see them in the field picker at the left. You might need to click pick fields
to bring up the full list.
got it. I still see default logs however. Do I need to put something else in my search string except for sourcetype=ias?
Did you go through this below. It has the details that you need to create a lookup.
http://docs.splunk.com/Documentation/Splunk/4.3.2/User/Fieldlookupstutorial
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources