Splunk Search

Automatic Lookup not working debug

user93
Communicator

Hello,

I've always had trouble with automatic lookups and every time I manage to do it it seems that I do it differently many times before it somehow works by magic.

I have a lookup table and a lookup definition. In the lookup table and the event logs I have a field to match that is in most events and I want to apply every field in the lookup table (30+ fields) to the events that included the matched field.

I've tried it two different ways. I have one table where the field name is different than in the source and I have a second table where the field name is the same.

eventlogs:
_time,ID,fieldx,fieldy,fieldz.
Lookuptable_v1:
ID,fielda-fieldw
Lookuptable_v2:
ID code, field a - field w.

I've tried matching the automatic input fields with the source where they were different, ID - ID code (and vice-versa). I've also tried just where the tables have the same field name.

Since I have 20+ fields I'm only adding one or two to the output areas until I get it to work, but it is not working. I either get an error that some fields have not been matched, OR it seems just like nothing has happened at all.

What gives?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...