Getting Data In

How to filter results between lookup and the results of the query?

bollam
Path Finder

Hello,

I have a lookup file which contains field and it’s values as follow.

Country location
India Andhra Pradesh
Himachal Pradesh
Madhya Pradesh
USA San Fransisco
San Andrea
Illinois
China Beijing
Jiangsu
Anhui

I have a query which gives the results as follow.

India Andhra Pradesh
India Madhya Pradesh
USA San Fransisco
China Beijing
China Anhui

I would like to filter out the one’s which are missing in the results and present in the lookup file.

Expected output:

India Himachal Pradesh
USA San Andrea
USA Illinois
China Anhui

Tags (1)
0 Karma

starcher
Influencer

Review these slides for the part about sentinel lookups
https://conf.splunk.com/session/2015/conf2015-LookupTalk.pdf

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...