Getting Data In

How do I search a match a specific source against an input lookup

blueumbrella
New Member

I am attempting to run the below, however I am not getting any results.
source="source.tsv" [|inputlookup appname| fields inputfield AS "field"]

I can search source="source.tsv" and get the fields displayed, and |inputlookup appname| fields inputfield AS "field" and displays fine, but when I attempt to combine them to get a match, I get no results. I understand that this only provides a result when there is a match but I have inserted a field that should trigger a match.

Can anyone please help point me in the right direction?

0 Karma

renjith_nair
Legend

@blueumbrella,

You could use just lookup instead of inputlookup

E.g.

source="source.tsv" |lookup appname  inputfield AS "field"  OUTPUT "your required fields from lookup"
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...