I get the following error:
"Error in 'inputlookup' command: This command must be the first command of a search."
FOR
source="/home/loart/dev/Splunk/Test_Logs/nepoc_access_small.log" | inputlookup month_year.csv
AND
source="/home/loart/dev/Splunk/Test_Logs/nepoc_access_small.log" | inputlookup month_year
However, inputlookup is indeed the first command, month_year.csv is defined, and month_year is a valid lookup.
To use inputlookup it must be the first command, e.g.
| inputlookup blah.csv
To use it later in a search you use it like so;
sourcetype=blah | inputlookup append=t blah.csv