Hello. I have an input lookup csv file with a single column named “Domain” that has a list of domain names in that column. I would like to loop through all those domain names and check if there are any events (from multiple indexes where I don’t want to worry about finding what Splunk field matches to “domain”) that include any of the domain names from my inputlookup csv. How would I build this search?
To clarify, you have a list of domain names in a field called "Domain" that you want to match against any field that contains the same text? If so, try this. It's not terribly efficient and could produce false positive, but it's a start.
index IN (foo bar baz) [ | inputlookup mylookupfile.csv | return 1000 $Domain ]