Hello,
I need a help with using wildcards in lookup.
I want to exclude from search results fields, which are located in lookup.
Example:
Search: host=* | search NOT [| inputlookup test_lookup.csv]
Lookup test_lookup.csv containts two fields:
exe,comm
/usr/sbin/useradd,*
I need to exclude all results which include exe="/usr/sbin/useradd" and any *comm* field.
I added WILCARD(comm) in lookup definitions, but it doesn't work.
transforms.conf
[test_lookup.csv]
batch_index_query = 0
case_sensitive_match = 1
filename = test_lookup
match_type = WILDCARD(comm)
What I did wrong? Thank you.
up
up