Splunk Enterprise

Can you extract fields after a lookup?

esalmon
Explorer

I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?

0 Karma
1 Solution

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing. 
r. Ismo

0 Karma

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

that's what you can always do and in any order and how many times you ever want.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...