Hi @roopeshetty,
you have to add an eval to your search:
| inputlookup WindowsTag.csv
| eval _raw=Servername." ".ServerIP." ".ServerLocation
| search $mytoken$
| fields - _raw
to have _raw in your fields to use for the full text search, that eventually you can delete at the end of the search.
Ciao.
Giuseppe
Hi @roopeshetty,
you have to add an eval to your search:
| inputlookup WindowsTag.csv
| eval _raw=Servername." ".ServerIP." ".ServerLocation
| search $mytoken$
| fields - _raw
to have _raw in your fields to use for the full text search, that eventually you can delete at the end of the search.
Ciao.
Giuseppe
Thanks Giuseppe, you fixed our issue instantly. really appreciate your help.
Hi @roopeshetty,
good for you, see next time.
Ciao and happy splunking.
Giuseppe
P.S.: Karma Points are appreciated 😉
Have you tried
| inputlookup WindowsTag.csv | search $mytoken$