Splunk Search

Automatic Lookup not working debug

user93
Communicator

Hello,

I've always had trouble with automatic lookups and every time I manage to do it it seems that I do it differently many times before it somehow works by magic.

I have a lookup table and a lookup definition. In the lookup table and the event logs I have a field to match that is in most events and I want to apply every field in the lookup table (30+ fields) to the events that included the matched field.

I've tried it two different ways. I have one table where the field name is different than in the source and I have a second table where the field name is the same.

eventlogs:
_time,ID,fieldx,fieldy,fieldz.
Lookuptable_v1:
ID,fielda-fieldw
Lookuptable_v2:
ID code, field a - field w.

I've tried matching the automatic input fields with the source where they were different, ID - ID code (and vice-versa). I've also tried just where the tables have the same field name.

Since I have 20+ fields I'm only adding one or two to the output areas until I get it to work, but it is not working. I either get an error that some fields have not been matched, OR it seems just like nothing has happened at all.

What gives?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...