Splunk Enterprise

Can I load multiple lookup files from one index?

silverKi
Path Finder

I'm practicing auto-lookup. Auto-lookup of vendors_ip.csv has already been successful in my index.
Here, I would like to add auto-lookup for the prices.csv file in the same index.
The process I followed uploaded a lookup table, created a lookup definition, and created an automatic lookup, but as a result of searching for index=main, only the prices.csv fields are not visible.
The fields of vendors_ip that were previously successful are output.
What I'm curious about is whether it is possible to perform multiple automatic lookups on one index in splunk.
I would also like to know why the automatic lookup is not working.

silverKi_0-1719984943252.png

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...