- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
how to map lookup field doesn't exist in splunk event
rakeshksingh
New Member
01-23-2019
11:29 AM
Hi All,
Could you please help me with a query to map a lookup table with splunk events but not aware on matching fields?
like:-
I have lookup table which contains url and i am not sure in which fields this contain in Splunk events. some are in field a , field b
If any splunk event get encountered with lookup table data , then alert has to triggered.
I tried with different queries but no luck.
Thanks
Rakesh
