I have a .csv list of domains I would like to search and I've uploaded it as a lookup table file.
The table is formated with a header of domain as:
My searchs are:
*[|inputlookup test_domains.csv | rename test_domains as domain | fields + domain]
The search completes with 0 results even though if I search for the domains indivdually there is definite activity to those test domains.
I'm can't figure out why i'm not gettting results when using inputlookup.
Any ideas or pointers?
Ok... I figured it out.
Our Splunk config doesn't contain an extraction for the field "domain" so I had to rename the domain field to field we use for domains.
View solution in original post