Splunk Enterprise

Can you extract fields after a lookup?

esalmon
Explorer

I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?

0 Karma
1 Solution

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing. 
r. Ismo

0 Karma

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

that's what you can always do and in any order and how many times you ever want.

r. Ismo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...