I want to pick up values from different lookup files according to the sourcetype.
| lookup errorrules.csv EventSubType Criticality OUTPUT waittime thresholdcount windowlimit
Say i have two source type 1 and type2
For type1 i want to lookup EventSubType and Criticalitytype1 in lookup errorrules.csv
For type2 i want to lookup EventSubType and Criticalitytype2 in lookup errorrules.csv
Please suggest the solution for this scenario if case needs to be used let me know how it will be implemented.
not sure i fully understand, but how about something along those lines:
... your search ... (sourcetype=1 OR sourcetype=2) ... | lookup error_rules.csv EventSubType Criticality OUTPUT wait_time threshold_count window_limit | eval Criticality_type1= if(sourcetype=="1",Criticality,null()) | eval Criticality_type2= if(sourcetype=="2",Criticality,null()) | .... more stuff if you want
... | eval Criticality = if(sourceype="type1", Criticality_type1, Criticality_type2) | lookup error_rules.csv EventSubType Criticality OUTPUT wait_time threshold_count window_limit | fields - Criticality