Splunk Search

How to check which lookup file or table have have an specific field

junier16
Explorer

im looking for the field "is_prohibited=true". This is field is located in one of lookup table, event type, or tag. How can i find out where that filed is  located ?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @junier16,

at a first sight it seems to be an eventtype, anyway you can search:

  • eventtypes and tags in [Settings -- Eventtypes],
  • for lookups see in [Settings -- Lookups -- Definitions],

for both there's a dedicated search function (remeber to remove the filters on top).

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...