Splunk Enterprise Security

How to fix - Lookup file working properly when running "inputlookup" command but in search time not all fields are extracted.

yossefn
Path Finder

I have a lookup file to add additional fields to events.
When running the "inputlookup" command I can see all the fields (4) just fine, but when running a search I see just 3 values from the 4 values in the table.
I've checked multiple times the spelling, removed and added the lookup but I still see just part of the lookup data.

Does anyone have an idea?
Thank you.

0 Karma

wmyersas
Builder

When you use a lookup, you're finding data in the table based on a field in your search data

Therefore, if you're doing a lookup on field1, you won't see it added in your output - because it was already there in your event data

0 Karma

gaurav_maniar
Builder

to assist better, please provide some example and query for the in which you are using the lookup.

nickhills
Ultra Champion

can you provide some examples?
Does your automatic lookup specify all 4 output fields?

If my comment helps, please give it a thumbs up!
0 Karma

yossefn
Path Finder

I can share, but it'll not help you since part of the data is in Hebrew.
I'm trying to make a lookup that will add data in English in addition to the Hebrew text so i'll be able to query in more efficient way.

What do you mean by "all 4 output fields"? It's all in the same field - different values. It's all door names in the same field.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...