Is it possible to store a search string in a lookup column, retrieve the content and run it as a search?
For example:
index=some_index
| lookup test.csv lookup_key_field as event_code OUTPUT spl_field as search_string
| ... some command to actually run the search_string ...
Like this:
index=some_index
| lookup test.csv lookup_key_field AS event_code OUTPUT spl_field AS search_string
| map search="search [|makeresults | eval search=$search_string$ | return $search_string]"
Hi Hoytn,
please try the below working example,
| makeresults | eval query="sourcetype=splunkd* | head 1" | outputlookup query_lookup.csv
Now get the result from lookup via sub-search,
index=_internal | search [| inputlookup query_lookup.csv | return $query]
Accept the answer if it helps.