I have a list of MAC addresses that indicate a unit is in production and a subsequent Perl script that pulls 10 at random every 10 minutes and populates a CSV that splunk has configured as a lookup. I then join that MAC to a subsearch to get the current IP address that corresponds to those random MAC addresses to get the current activity over 24 hours.
|inputlookup top10.csv | join mac [search source=stuff] | stats values(mac) by ipaddress
This works fine and is integrated in my dashboard as a simple results table.
The question is how can I use the returned value of the ipaddress field in a new or postprocess search?