Thank you for explaining about the input row. So, since I'm not searching an index in splunk but rather generating a report by doing an external lookup, it appears there is no other way than having one input and then expanding it into new rows, correct? Also, appreciate the two solutions, but both return duplicate entries for headline and state . First one: Second one:
... View more