Splunk Search

Automatic Lookup not working debug

user93
Communicator

Hello,

I've always had trouble with automatic lookups and every time I manage to do it it seems that I do it differently many times before it somehow works by magic.

I have a lookup table and a lookup definition. In the lookup table and the event logs I have a field to match that is in most events and I want to apply every field in the lookup table (30+ fields) to the events that included the matched field.

I've tried it two different ways. I have one table where the field name is different than in the source and I have a second table where the field name is the same.

eventlogs:
_time,ID,fieldx,fieldy,fieldz.
Lookuptable_v1:
ID,fielda-fieldw
Lookuptable_v2:
ID code, field a - field w.

I've tried matching the automatic input fields with the source where they were different, ID - ID code (and vice-versa). I've also tried just where the tables have the same field name.

Since I have 20+ fields I'm only adding one or two to the output areas until I get it to work, but it is not working. I either get an error that some fields have not been matched, OR it seems just like nothing has happened at all.

What gives?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...