I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?
I've worked it out, just perform the extraction within the search. I used the rex function
Hi
based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing.
r. Ismo
I've worked it out, just perform the extraction within the search. I used the rex function
Hi
that's what you can always do and in any order and how many times you ever want.
r. Ismo