All Apps and Add-ons

advanced lookup settings - multiple inputs

nandipatisunil
Path Finder

Does Splunk support looking up multiple inputs at the same time.
I have an advanced Query which has something line

Select ... from Table
where field1 = $input_1$ and field2 = $input2$

what is the search query syntax? trying something like
... | lookup lookup_name input_1, input2 output output_1

and getting an error
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table.

0 Karma
1 Solution

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

View solution in original post

somesoni2
Revered Legend

Try something like below:

...|lookup lookup_name input_1 as field1, input_2 as field2 OUTPUT yourcolumninlookuptooutput

Where input_1 and input_2 are fieldname in the lookupfile and field1 and field2 are your fields in events.

nandipatisunil
Path Finder

Thanks soni.

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...