I'm also facing the same issue, while using threatconnect app fields tag.name & tag.weblink in lookup command output. Actually, splunk supports dot notation on the normal lookups, i won't face issue on it. But on the threatconnect app, tag field is consist of name & weblink [key-value pairs]. While trying to access tag.name & tag.weblink in lookup command facing issue. Can anyone help on this.
... View more