When I do a search on events and lookup to a file, I get all the outputs on the left as fields and I can filter and see data on them, but the output fields do not appear in the event data itself int he main window or exports of that data. How do I get the Lookup table output fields to show there as well?
Interesting, one must use the As to define it as a local variable to use it in the main window, otherwise the field is only available in the filters on the left hand side. Maybe that's a bug.
So
| lookup user output UserGroup - does not work
| lookup user output UserGroup as UserGroup - works
Interesting, one must use the As to define it as a local variable to use it in the main window, otherwise the field is only available in the filters on the left hand side. Maybe that's a bug.
So
| lookup user output UserGroup - does not work
| lookup user output UserGroup as UserGroup - works