Splunk Enterprise version is 6.5.2
kvstore correlationsearches_lookup is defined in app SA-ThreatIntelligence (version 4.5.0) which is part of Enterprise Security (version 4.5.0).
The definition of correlationsearches_lookup is as below in :
But the command | inputlookup correlationsearches_lookup and | inputlookup correlationsearches_lookup | transpose | table column only shows 10 of 15 available fields.
May I know why the remaining 5 fields does not show in the result?
Is it possible to show all 15 fields in the result?
Thanks!
... View more