There is no conditional lookups concept in splunk. You can use SPL to achieve the same:
index=A | lookup mylookup fieldin1 OUTPUT fieldout1 | lookup mylookup2 fieldin2 OUTPUT fieldOUT2 | lookup mylookup3 fieldin3 OUTPUT fieldout3 | eval MyField= coalesce(fieldout1, fieldOUT2) | fillnull value="NULL" fieldout3 | where fieldout3="NULL"
Thanks!!!
There is no conditional lookups concept in splunk. You can use SPL to achieve the same:
index=A | lookup mylookup fieldin1 OUTPUT fieldout1 | lookup mylookup2 fieldin2 OUTPUT fieldOUT2 | lookup mylookup3 fieldin3 OUTPUT fieldout3 | eval MyField= coalesce(fieldout1, fieldOUT2) | fillnull value="NULL" fieldout3 | where fieldout3="NULL"
Thanks!!!
thx i will try it