Splunk Search

reverse wildcard lookup from event field in index


Hello Everyone

I am trying to see if i can pass an event field over to a lookup attached with a wildcard (reverse lookup from event filed) ? For this an example I will use the items below

table = usertable.csv
lookup = user

user_table.csv data below:
email, manager_name
user1@domain_1.com, "Doe, John"

I have an event field within an index of . I then have a lookup table (.csv) that contains a column email and manager_name* within the usertableloookup.

Is it possible to attach a wildcard to the username filed and send it against the lookup table to match the username portion of the email and return the manager_name from the lookup?

index=index1 username=user1 | lookup usertableloookup email AS username OUTPUT managername

username >> email
user1 >>>> user1@domain_1.com

