Thank you for the response. Still not capturing all the results I want. I am vetting results by doing this search:
| search [| inputlookup triggers | fields alert_msg]
| rename alert_msg as query
Using the above search, 6 events are being returned. Using your suggested search,
| eval alert_msg=mvappend(narrative, alarm_type)
| search [| inputlookup triggers | fields alert_msg]
Only 5 are being returned, missing one event "Major alarm set, CB 1 ESW PFE Port Fail" that has a narrative field matching value on the lookup table. If i change my search to this:
| eval alert_msg=mvappend(narrative, alarm_type)
| search [| inputlookup triggers | fields alert_msg] OR narrative="Major alarm set, CB 1 ESW PFE Port Fail"
| table alert_msg
All 6 events are being returned, with "Major alarm set, CB 1 ESW PFE Port Fail" being one of the new alert_msg field value. Also, I need to keep the alert_msg field for use on further data processing.
... View more