How do I use an eval where the final value is pulled out of a lookup file.?
Trying to use the following but cant get it to work;
| eval severity=if( | inputlookup severity_values.csv dest OUTPUT severity),"medium","high")
|Stats count by dest, severity
With a csv that looks as follows;
dest, severity
server1, high
server2, medium
server3, low
Thanks.
Greetings @jacqu3sy,
Assuming you have a field called dest
in your events, try this:
| lookup severity_values.csv dest as dest
| stats count by dest, severity
This will not allow me to OUTPUT the severity field, nor function within an IF statement as required.