Hi everyone,
I want to run this
sourcetype=x | lookup faup url
but am ONLY interested in url, url_scheme, url_port.
Is there a way to specify this, so that the other ones ( url_subdomain,url_domain_without_tld) are NOT generated.
Hopefully, this would also make it faster.
Thanks!
You can use OUTPUT option in the lookup command to specify which fields from lookup you want to display
sourcetype=x | lookup faup url OUTPUT url url_scheme url_port
See more information here
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Lookup