Splunk Enterprise

Can you extract fields after a lookup?

esalmon
Explorer

I'm trying to fix up some of the props.conf for the Windows Infrastructure app to match our Windows XML logs, but some of the fields needed are only provided after a lookup. Is there any way to extract fields post lookup?

0 Karma
1 Solution

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on this https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Searchtimeoperationssequence it’s not possible. And lookups is used only in search time not in indexing. 
r. Ismo

0 Karma

esalmon
Explorer

I've worked it out, just perform the extraction within the search. I used the rex function

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

that's what you can always do and in any order and how many times you ever want.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...