Hello, I have a lookup with url like url www.url.com .url.com site.url.com And i try to match it with my proxy logs to check if users access it. But i have issues with ".url.com" since it don't exactly matches the hostname. I have tried to replace them with "*.url.com" but splunk lookup don't match wildcard. I have tried things like this but nothing worked : | inputlookup all_url.csv | rename url as lookup_url | join type=inner [ search index=my-proxy | eval lookup_url="*" . lookup_url . "*" | search hostname=lookup_url ] Do you have any idea ? Thanks
... View more