Splunk Search

When a value isn't present in my automatic lookup table, how can I return a default result of "not found"?

daniel333
Builder

All,

I have an automatic lookup table working great, however, when a value isn't in my lookup table, I was hoping to have a default result of "not found". Any idea how I would tackle that?

thanks!

0 Karma

woodcock
Esteemed Legend

Go to Settings -> Lookups -> Lookup Definitions
Click on your lookup definition, check the Advanced options checkbox
In the Default matches text box add not found, then save.

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...