I have a csv file, generated each day from a Powershell script under the Splunk app lookups directory.
I use the info in those records with the
| inputlookup command in many other searches. The columns are name, surname and domain of the internal company network.
Is there a way to filter (in search time) only some of those records present in the .csv file (maybe in a wildcard fashion - for example: eliminate those which name start with adm*)?
Thanks for any suggestion,
inputlookup command is no different than using
index=myindex sourcetype=mysourcetype; you have all the same filtering options with additional pipelines of commands. The only difference is that you must do a
| search first. So you can do something like this:
| inputlookup | search NOT name="adm*"