**I have a below search query:**
| inputlookup splunk_report_test.csv
| where report_type="upcoming_offers"
| lookup vatson_splunk_report_test_lookup report_type outputnew _key as pKey,email_id,flag
| appendpipe
[| fields email_id,report_type,flag,pKey
| dedup pKey
| appendpipe
[| inputlookup vatson_splunk_report_test_lookup
| eval test_flag=if (match(pKey,_key),"close","open")
| fields email_id,flag,test_flag,pKey,test_key,report_type
| outputlookup test_vatson_test.csv]
]
| table name,age,country,email_id,flag,pKey,test_flag,pkey_list
My pKey value is not getting passed to the inner most inputlookup query. I need the pkey value passed to my below query:
[| inputlookup vatson_splunk_report_test_lookup
| eval test_flag=if (match(pKey,_key),"close","open")
| fields email_id,flag,test_flag,pKey,test_key,report_type
| outputlookup test_vatson_test.csv]
]
How can I achieve this?
TIA !!
... View more