I created the below automatic lookup through Splunk 6 web.
app_info host AS host gate AS gate OUTPUTNEW app AS app
If I use this lookup in a search it works as expected. However, when simply searching the source the output field is not displayed.
Am I missing something?
I've found that the automatic lookups don't work with apps that they are not created under. Either 1 you will need to move the config settings to system, or 2 create the same lookup again for each app(and upload multiple csv files)
Here is some info on setting it up to be in system instead of a specific app: