Everyone in my organization has a unique username, which I have extracted from my search as "anumber".
I want to construct an external lookup script to convert this "anumber" extraction into human names.
All of these anumbers are convertible via an AD lookup, which I have scripted.
This is basically what I want to achieve, in my fields I want to be able to see both anumber and humanname, for example:
anumber = "a00001"
humanname = "Michael Someone"
I have written a python script which works as follows...
Now, two questions...
1) Is this script output okay, or does it need to be formatted differently...?
2) How do I now add this scripted lookup into splunk? (preferably with the GUI, what needs to be done under "Lookups")