I try to edit lookup file through the lookup file editor, but below message is shown. The file is too big to be edited (must be less than 10 MB) Is there any workaround other than reducing the lookup...
I would like to know about to add a single field value to outputlookup, as currently there are some fields like id, condition, value is there , but the need is only to ingest condition, Can anyone p...
...f the hosts we would need to be using are quite big. I thought about using lookup in a subquery but don't know how to approach it so it makes sense.
Hi All, I have the below search. I am being told it appends results to a lookup table called user_ids.
index=ad earliest=-15d
|stats latest(_time) as _time, latest(p...
Hello All, I have a quick question about comparison fields from a lookup table. Just imagine that I have a query like this. index=linux [|inputlookup suspicious_commands.csv where c...
...bsp; I can't seem to figure out how to go about this. I have no problem breaking apart the multivalue and rejoining it, I just can't figure out how to do a lookup that falls within a two fields... R...
KV store lookups are failing with the following error:
Error in 'inputlookup' command: External command based lookup 'kvstore_lookup' is not available because KV Store initialization has failed....
Hi All, I have a .csv file named Master_List.csv added to splunk lookup. It has the values of the fields "Tech Stack", "Environment", "Region" and "host" and has about 350 values per field. A...
I am having some trouble performing a search across multiple lookup tables. I have several csv's as lookup tables (let's say table1.csv, table2.csv, table3.csv), all of which have the same field n...