Splunk Enterprise

Can you extract fields after a lookup?

esalmon
Explorer

I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?

0 Karma
1 Solution

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing. 
r. Ismo

0 Karma

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

that's what you can always do and in any order and how many times you ever want.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...