Splunk Search

Matching value inside a lookup with wildcard?

zewashere
New Member

Hello, i'm new to Splunk and i need some advices.

I've created a lookup named my_color_lookup, with 2 column :

color,danger

red,high

yellow,medium

green,low

Then my base search is :

sourctype=foo AND customer_id=520.

This search returns me a quantity of event and has several fields. One of these fields is src_light.

I want to create a new field "risk_level" in my event

if src_light match with one color inside my lookup, i want my search to

- add a value low or medium or high in the new field risk_level

- leave the field risk_level if ther's no matching.

Thanks for your help and suggestions

Labels (1)
0 Karma

zewashere
New Member

one last things, i need to use wildcards for the search... the field src_light can have value like "dark yellow" or "deep red" and these colors need to match.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...