All Apps and Add-ons

lookup multiple inputs

chvnc
Explorer

Hi,

one field has two values while use multiple input field within a lookup command and not getting the output.
The lookuptable looks like this:

env id file

eservices 123 abc123
xyz 456 abc456

I tried it like this, but it didn't work:

passing the env and id values in query and then
| lookup lookup.csv env,id OUTPUT file

if I pass only env=xyz its working but if two values are passed its not working.

0 Karma

sundareshr
Legend

Try this

.... | eval env_id=env." ".id | lookup "env id" AS env_id OUTPUT file
0 Karma
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...