I want to build a chart using external fields through look up table in Splunk Enterprise Security. After a week, I got to know that I also getting new data formatted data in the same fields which i was using it. So now, I couldn't capture those new data count into my chart. I want to create one another field called "UNKNOWN" for those not matching look up data. Can anyone please help me with it ?