Hello,
I have a lookup table with fields user and src.
I want to table results [user src] where the src within my search != the src listed within the lookup table.
So first I need to search for matching user rows, then I need to compare the src of the search with the src value in the lookup file.
If the src is different, I want to table the new src value from the search.
Can someone help me with this? Thanks so very much.
Hi @epw0rrell
Try the following
index=* <<Your Other Search Criteria>>
| lookup your_lookup_table user AS user OUTPUT src AS lookup_src
| where isnotnull(lookup_src) AND src != lookup_src
| table user src
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will
Hi @epw0rrell
Try the following
index=* <<Your Other Search Criteria>>
| lookup your_lookup_table user AS user OUTPUT src AS lookup_src
| where isnotnull(lookup_src) AND src != lookup_src
| table user src
Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards
Will