Splunk Enterprise

Can I load multiple lookup files from one index?

silverKi
Path Finder

I'm practicing auto-lookup. Auto-lookup of vendors_ip.csv has already been successful in my index.
Here, I would like to add auto-lookup for the prices.csv file in the same index.
The process I followed uploaded a lookup table, created a lookup definition, and created an automatic lookup, but as a result of searching for index=main, only the prices.csv fields are not visible.
The fields of vendors_ip that were previously successful are output.
What I'm curious about is whether it is possible to perform multiple automatic lookups on one index in splunk.
I would also like to know why the automatic lookup is not working.

silverKi_0-1719984943252.png

0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...