Splunk Search

Where to download lookup file related to sales index (retail sales) used in search tutorial ?

Ombessam
Path Finder

count retail sales events for strategy gamescount retail sales events for strategy games

 

I can't find categoryId field by default from the search tutorial data. It has been added by a lookup file but I don't know where can I download it.

Can anyone help help this ? Thanks

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

categoryId is not used in the vendor_sales sourcetype - try looking in the access_combined_wcookie sourcetype (there is no additional lookup for this information).

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

categoryId is not used in the vendor_sales sourcetype - try looking in the access_combined_wcookie sourcetype (there is no additional lookup for this information).

0 Karma

Ombessam
Path Finder

@ITWhisperer  you're right, the correct source type is  access_combined

 Screenshot 2025-03-19 at 17.26.32.png

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...