Splunk Search

How can I use lookup as a filter?

test_qweqwe
Builder

Hello
When the value of lookup equal to result of event = do not show that event.
How to create kinda search?

1 Solution

jkat54
SplunkTrust
SplunkTrust
... NOT [|inputlookup lookupname | fields field1 field2 | format]

View solution in original post

jkat54
SplunkTrust
SplunkTrust
... NOT [|inputlookup lookupname | fields field1 field2 | format]

View solution in original post

.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!