HI all,
Is it possible to create an automatic lookup with a partial match?
This means in the lookup table is "user*" and this should automatically match with every log like "user1", "user2"...
Regards,
Caspar
You cannot do it if the lookup file contains user
but if you add an asterisk to each entry in the lookup file (so that user
becomes user*
) then you can. See this link for a nearly identical Q&A:
http://answers.splunk.com/answers/52580/can-we-use-wild-characters-in-lookup-table.html