Ciao @gcusello Thank you for your continued help. I must be doing something fundamentally wrong. If I run the search as you describe it, it returns zero results. Current setup Index = "myIndex" eventtype = "myEventtype" returns 1196 events Lookup file "known-events" contains a single event, identified by the "composite primary key": _time, host, source_file I would thus expect that the query you provided returns 1196 - 1 results. To adress your point and make sure that the field names are the exact same, I tried this: index = myIndex eventtype = myEventtype
| fields _time, host, source_file
NOT
[| inputlookup known-events.csv
| fields _time, host, source_file ] This gives the following error: Error in 'fields' command: Invalid argument: 'source_file=some_file_name-[some-host_name].txt' I am not quite sure what to make of this
... View more