I have a lookup as mentioned below:
Message#, MessageDesc
1234, Error
In my search criteria,I am getting output like
Message#, Code, _raw,_time
1234, abcd, this error 1234 caused issues, 2017-02-21 06:40:32
Now I want my complete output as
Message#, MessageDesc,Code, _raw,_time
1234,Error, abcd, this error 1234 caused issues, 2017-02-21 06:40:32
I tried different options but not able to get the _raw and _time values
You need to do other way around. Try this (check the field names should be exactly same)
your current search giving fields Message#, Code, _raw,_time
| lookup yourlookup.csv "Message#" OUTPUT MessageDesc
| table Message#, MessageDesc,Code, _raw,_time
You need to do other way around. Try this (check the field names should be exactly same)
your current search giving fields Message#, Code, _raw,_time
| lookup yourlookup.csv "Message#" OUTPUT MessageDesc
| table Message#, MessageDesc,Code, _raw,_time
Thanks I was able to figure out the issue and have used the same logic but thanks a lot for the prompt help