I have a raw event from where i want to capture a few specific fields already configured in splunk and want to create a kind of lookup data which will capture a record from an existing field and outlined based on lookup instruction.
aaad00 – if d, it should be captured under data
aaan00 – if n, it should be captured under name
At the highest level simply append | outputlookup my_lookup_name.csv to the end of your search. That said can you share a bit more on what it is you are trying to capture with some examples of the data or the desired state?