Hello,
I have a lookup with 3 fields "Hostname" "IP" "Status" ( Status is by default set with the value "Non-Active")
Hostname IP Status
AA 10.x.x.x Non-Active
BB 10.x.x.x Non-Active
CC 10.x.x.x Non-Active
Now I did a search using lookup to find what all servers are currently reporting to Splunk :
Result :
Host reporting to Spunk
AA
CC
Based on the result I want to update the value of field (Status as "Active") in existing lookup
So the result I am expecting :
lookup table looks now :
Hostname IP Status
AA 10.x.x.x Active
BB 10.x.x.x Non-Active
CC 10.x.x.x Active
|eval Status=Active | join type=left [|inputlookup table] |outputlookup