Splunk Search

Lookup Definition - Default Matches not working as expected

jackreeves
Explorer

Hi,

I have built a lookup table, definition & automatic lookup.

I've set the definition to;
Min Matches - 1
Max Matches - 1
Default Matches - None

The additional lookup fields appear in the appear data as expected with 1 result having the value of "None". However, when I click the "None" value it appears as no results found. If I then add a wildcard value before the "*None", the one result in question appears.

Has anyone else come across same issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...