- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

We're using the Azure Monitoring Data Add-on to integrate Splunk and Azure. The Azure events have the subscription ID value (fields name is am_subscriptionId) in each of the events. I would like to be able to put a name/email address to the subscription. I have a lookup table configured which has the fields subscriptionID, subscriptionName, and subscriptionContact. I have attempted to use lookups to no avail. Below is my search. I would like to have a table result with the am_subscriptionId, subscriptionName, and subscriptionContact displayed.
index=* sourcetype=amal:security
| lookup azure_subscription_id_to_support_group subscriptionID AS am_subscriptionId OUTPUT subscriptionName
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


This issue may have to do with case sensitivity on lookups. By default, lookups are case sensitive, but you can change this by modifying transforms.conf like so:
[azure_subscription_id_to_support_group]
case_sensitive_match = 0
filename = azure_subscription_id_to_support_group.csv
Or, you can do this in the UI too by going to Settings -> Lookups -> Lookup definitions -> azure_subscription_id_to_support_group -> Advanced options -> uncheck Case sensitive match
Everything else looks good.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


This issue may have to do with case sensitivity on lookups. By default, lookups are case sensitive, but you can change this by modifying transforms.conf like so:
[azure_subscription_id_to_support_group]
case_sensitive_match = 0
filename = azure_subscription_id_to_support_group.csv
Or, you can do this in the UI too by going to Settings -> Lookups -> Lookup definitions -> azure_subscription_id_to_support_group -> Advanced options -> uncheck Case sensitive match
Everything else looks good.
