Your search works, but my expected results are events from lookup not main index This is my lookup data asn,classification,confidence,country,date_first,date_last,detail,id,itype,lat,lon,maltype,org,resource_uri,severity,source,actor,tipreport,type,srcip,domain,md5,email,url And all event data contains a ip field and not the same name. The schedule must be All day, because any incoming event log from main index can be in lookup, and vice versa
... View more