This doesnt return anything when i know there are many events with the usernames in the message!
this returns a list of the usernames correctly
|inputlookup list.csv | fields UserLogonName
i have an extracted field called Messsage that will have the username SOMEWHERE in the message
index = blah Message=”|inputlookup list.csv | fields UserLogonName”
Thsi doesnt work, no results retrned!
PLease help!
thanks!
You will need t use a subsearch to perform that kind of search.
Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial
and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork
This should get you to where you need to be.
Good luck, hope this helps,
MHibbin
You will need t use a subsearch to perform that kind of search.
Please read http://docs.splunk.com/Documentation/Splunk/latest/User/Subsearchtutorial
and http://docs.splunk.com/Documentation/Splunk/latest/User/HowSubsearchesWork
This should get you to where you need to be.
Good luck, hope this helps,
MHibbin