You can begin a search with a pipe command, but only if that command creates events, which inputlookup
does. So a search like this should work:
| inputlookup delivery.csv | lookup order.csv key OUTPUT delivery_status | where delivery_status="failed"
Do you want to have it like this?
| inputlookup delivery.csv
| lookup order.csv key OUTPUT delivery_status
I want to find out the "name" where delivery_status is "failed".
Before this command do i need to add index=*?
can u give me a exact command?