I have a challenge where I want to place a static field (at index-time, NOT search-time) onto events as they are indexed.
The value of this new field must be from a lookup, based upon data already in _raw.
Lets assume the REX we need to extract here the value to be looked up is:
Test Location:(?<valueToLookup>[0-9.])*
Can anyone help me with code samples on how to then use valueToLookup to create a new field called resolvedLookupAtIndex so it appears as a static field?
NB: I have a separate search head vs indexer environment.
I did thanks, I spoke to someone at the last Splunk Live in London and confirmed this - thanks for adding an answer though.