Does Splunk support looking up multiple inputs at the same time.
I have an advanced Query which has something line
Select ... from Table
where field1 = $input_1$ and field2 = $input2$
what is the search query syntax? trying something like
... | lookup lookup_name input_1, input2 output output_1
and getting an error
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.
Try something like below:
...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput
Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.
Try something like below:
...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput
Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.
Thanks soni.