I am using a CSV lookup that adds additional fields to my Splunk search results...
date_month=october OR date_month=june | lookup mylookup month as date_month
So it's matching the date_month field in my search results with the month column in my CSV file and returning the 'shortname' as a new field.
However, I want to use data in my CSV file to initiate the search instead. I want to do a lookup that will return all of the months in the month column of my CSV file, and then do a search on them, while including the additional 'shortname' field in the search results?
I got this far:
| inputlookup myiplookup | fields month
Which returns the list of values in my CSV 'month' column, but it doesn't actually search on them, and doesn't return the 'shortname' field.