Hi,
The usual way of using lookup tables is to get a value from a searh, do a lookup in a lookup table and output a value from a different column if it matches.
The traditional method would be sourcetype=xxx | lookup lookup.csv cs_host as cs_host OUTPUT XXX column
Now, i would like to use my lookup table, which contains a list of values (cs_host) for example,
and run a search on my proxy logs for all records that are within the cs_host field in the lookup table. Its kinda like a reverse lookup using the lookup tables. any tips?
Much Appreciated
Hey thanks Ayn,
is it
sourcetype=xxx [inputlookup lookup.csv | fields cs_host]
or
sourcetype=xxx [| inputlookup lookup.csv | fields cs_host]
with the extra | before inputlookup?
It's as easy as this:
sourcetype=xxx [inputlookup lookup.csv | fields cs_host]
The subsearch will expand into a filter list containing all values for cs_host in your lookup.