HI Folks,
I'm trying to get automatic lookups working for a custom CSV file import. I'm trying to key in on two fields that have similar host names, but not exact. Is there a way to use something like contains versus equals?
Examples:
CSV Lookup Field: WAN_device_dns
Splunk Field: Host
CSV Lookup Field value: washington_bah.domain.com
Splunk Fields value: washington_bah-loop7
I'd like to equate these fields as the same in the automatic field association if the beginning matches since my CSV script automatically generates externally. If not, I'll have to rewrite the CSV output.
Thanks all,
G1
... View more