Splunk Search

inputlookup help no result- match substring in extracted field

r999
Path Finder

This doesnt return anything when i know there are many events with the usernames in the message!

this returns a list of the usernames correctly
|inputlookup list.csv | fields UserLogonName

i have an extracted field called Messsage that will have the username SOMEWHERE in the message

index = blah Message=”|inputlookup list.csv | fields UserLogonName

Thsi doesnt work, no results retrned!

PLease help!

thanks!

0 Karma
1 Solution

MHibbin
Influencer

You will need t use a subsearch to perform that kind of search.

Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial

and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork

This should get you to where you need to be.

Good luck, hope this helps,

MHibbin

View solution in original post

0 Karma

MHibbin
Influencer

You will need t use a subsearch to perform that kind of search.

Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial

and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork

This should get you to where you need to be.

Good luck, hope this helps,

MHibbin

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...