I have a lookup table that contains the data similar to the: Service_name, IP, Port
HTTPS, 10.10.10.10, 443
DNS, 10.10.10.11, 80
What I am trying to achieve is to make a search that'll compare existing IPs and ports from the logs that are in fields destip, destport and return values that match both, i.e. if "destip = IP & destport = Port then return service_name but I don't know how to achieve this in SPL.
I can match destip with the IP from the lookup and return a new field for service_name based on that but that doesn't help me achieve what I need
| lookup service_lookup IP AS destip OUTPUTNEW service_name
I was able to get what I wanted off of what you had here, eventually even decreased the search query to | lookup service_lookup IP as destip Port as destport OUTPUTNEW service_name
Which matched the port & ip from the logs to the table and then created a new field named "service_name" based on the results.