Hello
I need to give a lookup table search the ability to use wildcards against the values contained in the lookup file, as per this example here:
However, I am using Splunk Cloud, and do not have shell access to edit the transforms.conf. I do not see any option in the Cloud GUI for adding these directives. I should point out that I want to use the accepted answer, not the undocumented answer of inclusion of *
in the lookup file, which doesn't seem to work.
Thanks.
There is a configuration that Cloud Operations needs to set for you. Please open a support ticket and request that your lookup be configured for wildcards, and attach the configuration to the ticket.