I have two lookup tables:
notablesIp.csv and criticalAsset.csv
How would I write a search that would tell me a notable happened on a critical asset?
They share a common field called IP.
I have never been able to get this search to work even though I see multiple references to just this search @to4kawa. What version of splunk are you using? Because in Splunk Enterprise 8.0.1 this search gets an error.
Error in 'inputlookup' command: This command must be the first command of a search.
Which is why I used the
join command by the field
this is perfect also I added the lookup to the kv store so now it is
| inputlookup notableIP | join ip [| inputlookup CriticalAsset]
We are using Splunk ver 7.2