Getting Data In

How to use a lookup with wildcard based fields to search for matching field combinations?

DrFedtke
Explorer

Hi all.

My scenario is:

1) lookup table with fields 3 fields

msgId,msg,critical
SHK5*,*BLABLABLA*,yes

2) events/incidents should be enriched with the field critical in
case BOTH fields of the lookup table (msgId and msg) are matching
(i.e. both are AND-related, not OR-related)

for example, the message

SHKI5544 BLABLABLA should match, but
SHKI5544 LALALALA not


my props.conf:

[sf_splunk_assessment]
...
LOOKUP-assessmentOperationProblem = assessment_lookup_operation_problem msgId , msg

my transforms.conf:

...
[assessment_lookup_operation_problem]
filename = Operation_Problem_Detection.csv
match_type = WILDCARD(msgId,msg)
max_matches=2
min_matches=1
default_match=---
case_sensitive_match=false

======================

But it does not work.

Then I have a problem to exactly understand "max_matches":
Does this value refer to a lookup given by both and related values, or does each one, msg and msgId, counts +1?

And in general, how does max_matches > 1 work? Will the looked-up value become part of any subsequent lookup? or does the lookup process always use the original value?

Thanks for any feedback.

best
stephen

0 Karma

thirumalreddyb
Communicator

your search query with data ..... | lookup msgId msg OUTPUT critical

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...