Splunk Enterprise

Can I load multiple lookup files from one index?

silverKi
Path Finder

I'm practicing auto-lookup. Auto-lookup of vendors_ip.csv has already been successful in my index.
Here, I would like to add auto-lookup for the prices.csv file in the same index.
The process I followed uploaded a lookup table, created a lookup definition, and created an automatic lookup, but as a result of searching for index=main, only the prices.csv fields are not visible.
The fields of vendors_ip that were previously successful are output.
What I'm curious about is whether it is possible to perform multiple automatic lookups on one index in splunk.
I would also like to know why the automatic lookup is not working.

silverKi_0-1719984943252.png

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...