Splunk Search

Enriched event data

pbenner
Explorer

I need to enrich my event data (web logs) with several other fields based on a value of one of the events fields. I plan to use a lookup that calls an script to go get the fields.

When I run the search again, containing the lookup, will it go and lookup events that were already looked up? Does splunk know to only enrich events that not yet enriched?

Tags (1)
0 Karma

pbenner
Explorer

Looks like OUTPUTNEW is the answer.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...