Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I add fields from a lookup table to my search event?

$
0
0
I have a lookup table geo-lookup.csv which has data in the format: IP, Coordinates, Location. My search has the field ipAddress which is used as the filter to match the IP field in the table. I want the Location field to be added to the search events for the matching ipAddress field. I'm using the command: base search | lookup geo-lookup IP as ipAddress OUTPUTNEW Location as location Can anyone tell me where I'm going wrong? All my permissions and lookup definitions are configured correctly.

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>