Splunk Search

Lookup: Replace / Create new field


For example:
When I run search and see field Sub_Status - 0xC0000064 I wanna new field that will explain what the code is it.
alt text

0 Karma
1 Solution
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!