Splunk Search

inputlookup help no result- match substring in extracted field

r999
Path Finder

This doesnt return anything when i know there are many events with the usernames in the message!

this returns a list of the usernames correctly
|inputlookup list.csv | fields UserLogonName

i have an extracted field called Messsage that will have the username SOMEWHERE in the message

index = blah Message=”|inputlookup list.csv | fields UserLogonName

Thsi doesnt work, no results retrned!

PLease help!

thanks!

0 Karma
1 Solution

MHibbin
Influencer

You will need t use a subsearch to perform that kind of search.

Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial

and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork

This should get you to where you need to be.

Good luck, hope this helps,

MHibbin

View solution in original post

0 Karma

MHibbin
Influencer

You will need t use a subsearch to perform that kind of search.

Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial

and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork

This should get you to where you need to be.

Good luck, hope this helps,

MHibbin

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...