Splunk Search

Lookup several times in a KVstore?


I'm working on a kvstore that has multiple interesting columns with which i might determine to enrich an event.

For example, | lookup kvstore a as a

which of course works fine if a exists in the kvstore. However, if this doesn't match to a record,
i'd like to | lookup kvstore b as bif the first one fails, and on and on onto c and d and so on until i find a matching lookup and output that row.

I've tried this by simply putting several lookups after each other as such:

| lookup a as a
| lookup b as b
| lookup c as c

but this breaks, because if a matches I'm happy, i dont need the other lookups, however if a doesn't match, i still need to progress with further lookups..

Does anyone have a solution for this issue?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!