All Apps and Add-ons

advanced lookup settings - multiple inputs

nandipatisunil
Path Finder

Does Splunk support looking up multiple inputs at the same time.
I have an advanced Query which has something line

Select ... from Table
where field1 = $input_1$ and field2 = $input2$

what is the search query syntax? trying something like
... | lookup lookup_name input_1, input2 output output_1

and getting an error
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.

0 Karma
1 Solution

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

View solution in original post

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

nandipatisunil
Path Finder

Thanks soni.

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...