I have a lookup file titled airports.csv. In the file, i have several fields, but one is AirportCode. This field has several thousand 3 letter airport codes. I need to query to see if these three letter codes, concatenated with an "=" symbol, appear anywhere in a particular field in my sourcetype titled URL. The end result is essentially a query that searches URL="*=AirportCode*"
lookup: airports.csv
lookup field: AirportCode
sourcetype: sct
sourcetype field: URL
I've used the below in testing my lookup and it works fine
[|inputlookup airports.csv | rename AirportCode as Airport | fields + Airport | head 1 ]
I've also tested with this, but it seems like it returns the presence of AirportCode anywhere in the logs, not just within the URL field. From here I've yet to have any luck using eval to concatenate the "=" and not get an error.
index=IDX sourcetype=sct |lookup airports.csv AirportCode as URL
I know I'm still a ways off, so any guidance is appreciated.
... View more