Splunk Search

How would I create a search that returns events that matches a field in a lookup table?

Splunk_God
Engager

Lookup:

Value:

Success
Error
Undetermined
Info
debug

So if value in the events at anytime matches any of the fields listed in the above(my lookup) I would want to get an alert. Could I leverage inputlook?

Thanks

Tags (3)
0 Karma

reswob4
Builder

So I had a very similar question. Here is the narrative for how I resolved my issue.

http://answers.splunk.com/answers/193753/what-is-the-best-way-to-compare-search-results-to.html

credit for help again goes to @martin_mueller and @musskopf.

0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...