All Apps and Add-ons

advanced lookup settings - multiple inputs

nandipatisunil
Path Finder

Does Splunk support looking up multiple inputs at the same time.
I have an advanced Query which has something line

Select ... from Table
where field1 = $input_1$ and field2 = $input2$

what is the search query syntax? trying something like
... | lookup lookup_name input_1, input2 output output_1

and getting an error
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.

0 Karma
1 Solution

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

View solution in original post

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

nandipatisunil
Path Finder

Thanks soni.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...