hi
I use the subsearch below in order to match host in host.csv with host in the index
But in the index, the host field is called USERNAME
So I am doing a rename in my subsearch but I am unable to match with the index events
what is the problem please??
[| inputlookup host.csv
| table host| rename host as USERNAME ] index=A sourcetype=wireless USERNAME=TOTA
Hi @jip31,
Maybe USERNAME=TOTA
is causing the problem as it only filters on TOTA. Try it as follows :
index=A sourcetype=wireless [| inputlookup host.csv | table host| rename host as USERNAME ]
If you want to enrich your data with the lookup then this should do :
index=A sourcetype=wireless | lookup host.csv host AS USERNAME
Best regards,
David
Hi @jip31,
Maybe USERNAME=TOTA
is causing the problem as it only filters on TOTA. Try it as follows :
index=A sourcetype=wireless [| inputlookup host.csv | table host| rename host as USERNAME ]
If you want to enrich your data with the lookup then this should do :
index=A sourcetype=wireless | lookup host.csv host AS USERNAME
Best regards,
David
thanks to you
I think you need to place the search before the lookup, so it would look something like this
index-A sourcetype=wireless USERNAME=TOTA [inputlookup host.csv | table host | rename host as USERNAME]
See if that works perhaps?
its not working...