You have a couple different ways to do this. if you have say 10000 items in the lookup table.. but 10Million in the index many of which are NOT in the lookup then you probably want to use it as part of the search. index=<indexname> [ | inputlookup <filename> | fields combinedrules{} | format] | append [ | inputlookup <filename> | eval sourcetype=lookupfile ] |stats dc(sourcetype) AS sources by combinedrules{} | eval Search_Index=if(sources > 1,"Yes","No") | eval Inputlookup_File = "Yes" If you want to know if a value is IN the index but not the lookup file.. then: index=<indexname> | append [ | inputlookup <filename> | eval sourcetype=lookupfile ] |stats dc(sourcetype) AS sources values(sourcetype) AS sourcetype by combinedrules{} | eval Search_Index=if(sources > 1 OR NOT match(sourcetype,"(lookupfile)"),"Yes","No") | eval Inputlookup_File =if(match(sourcetype,"(lookupfile)"),"Yes","No") |fields combinedrules{},Search_Index,Inputlookup_File
... View more