Splunk Enterprise

Can you extract fields after a lookup?

esalmon
Explorer

I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?

0 Karma
1 Solution

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing. 
r. Ismo

0 Karma

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

that's what you can always do and in any order and how many times you ever want.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...