Hi, I'm trying to get wildcard lookups to work using the "lookup" function. I've followed guidance to set up the "Match Type" for the fieldin the lookup definition as per Define a CSV lookup in Splunk Web - Splunk Documentation (I don't have access to transforms.conf) and whatever I try, adding WILDCARD(foo) makes no difference, as if the feature is not being applied. I've found several posts where people report success, but cannot replicate myself. Lookup example: foo bar abc 1 *cba* 2 | makeresults | eval foo="x" | lookup mylookup foo x="abc" matches x="*cba*" matches x="ab*" does not match x="dcba" does not match I'd rather not resort to inputlookup subsearches if possible as my applications are quite complex! Splunk Verision: 8.2.2.1 Many Thanks in Advance
... View more