During search I got table like this
I have lookup users.csv, which looks like this
I want to compare my table with lookup and if host and user matches, return my table (time, host, user, action, result), thus on this example I want to get in results table:
(because in second line user not matches). Thank you in advance.
if you could share your search I could be more detailed, anyway, the inputlookup command in a subsearch is the solution for your need.
please try something like this (adapting to your search:
index=your_index [ | inputlookup users.csv | fields host user ] | table time host user action result
I supposed that the columns of the lookup are host and user.
found out the reason why it's not working
it's because there is no original field "user" in logs, I get user with rex command
so it works with | inputlookup ... | fields host, but not working with | inputlookup ... | fields host user