Splunk Search

Events mismatch values with lookup values

LogUx
Motivator

Hello Splunkers!!

We have events that contains source and destination fields with complete values, and we want to match these fields against event data where the corresponding fields (source and destination) may include wildcard values in the lookup. The goal is to accurately match the event data with the appropriate lookup values, ensuring that wildcard patterns in the lookup are properly evaluated during the matching process.

uagraw01_1-1732174446045.png

Values to be match with below lookup.

uagraw01_2-1732174790327.png

What I have tried so far to match events field values with the lookup field values. But no luck found. Please give me some suggestion to execute this correctly.

| lookup movement_type_ah mark_code as mark_code destination as destination source as source OUTPUTNEW movement_type

 

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @LogUx ,

what's the issue?

did you unflagged the checkbox for exact match in the Lookup Definition?

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @LogUx ,

what's the issue?

did you unflagged the checkbox for exact match in the Lookup Definition?

Ciao.

Giuseppe

LogUx
Motivator

@gcusello As per the below screenshot, I need to specify in the match_type for both the fields ?

uagraw01_0-1732175319306.pnguagraw01_0-1732175319306.png

FYI @gcusello  I have added below entries and it starts working as expected.

WILDCARD(source), WILDCARD(position), WILDCARD(destination)

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @LogUx ,

good for you, remember to unflag the Case sensitive match.

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...