Yes they match, even though they are part of an fqdn I can see them in raw data when I query for them using ...|rename host as search|format .
Also splunk produces a list of matching indices when I use the query [|inputlookup hosts.csv|table host|rename host as search|format]|stats values(index) .
I just am struggling to append the index list with the hostnames from the lookup.
... View more