Hello everyone, I'm a beginner in using Splunk. I'm facing an issue in finding a search solution for the following idea: I'm logging the deletion behavior of files, and I have whitelisted some important files in a lookup. If the file_path in the event matches any of the file_paths in my lookup file, then it should produce a result. Here is the initial search, and it found 2 file_paths. This is my lookup file. Here is my search, but it's not working correctly. Thank you, everyone, for reading!
... View more