Splunk Search

Is it possible to create an Automatic Lookup with partial match using a wildcard?

DrFedtke
Explorer

HI all,

Is it possible to create an automatic lookup with a partial match?
This means in the lookup table is "user*" and this should automatically match with every log like "user1", "user2"...

Regards,
Caspar

0 Karma

woodcock
Esteemed Legend

You cannot do it if the lookup file contains user but if you add an asterisk to each entry in the lookup file (so that user becomes user*) then you can. See this link for a nearly identical Q&A:

http://answers.splunk.com/answers/52580/can-we-use-wild-characters-in-lookup-table.html

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...