Getting Data In

How do I search a match a specific source against an input lookup

blueumbrella
New Member

I am attempting to run the below, however I am not getting any results.
source="source.tsv" [|inputlookup appname| fields inputfield AS "field"]

I can search source="source.tsv" and get the fields displayed, and |inputlookup appname| fields inputfield AS "field" and displays fine, but when I attempt to combine them to get a match, I get no results. I understand that this only provides a result when there is a match but I have inserted a field that should trigger a match.

Can anyone please help point me in the right direction?

0 Karma

renjith_nair
Legend

@blueumbrella,

You could use just lookup instead of inputlookup

E.g.

source="source.tsv" |lookup appname  inputfield AS "field"  OUTPUT "your required fields from lookup"
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...