Splunk Search

Is there a way to apply lookup table in a real time search?

jadengoho
Builder

Hi all,
I just want to ask if there is a way that I can apply a lookup table in a real-time search?
I have this column that contains all the Ip address generated by servers, and in the lookup table are the names of specific ip addresses.
This will be easy in a timely/relative search but in my situation, the codes are running in real-time, is there a way that I can do it?
Thanks in advance.

0 Karma
1 Solution

HiroshiSatoh
Champion

It is available in the manual. Why did you think you could not do it?

Real-time searches can take advantage of all search functionality, including advanced functionality like lookups, transactions, and so on. There are also search commands that are to be used specifically in conjunction with real-time searches, such as streamstats and rtorder.

https://docs.splunk.com/Documentation/Splunk/7.1.0/Search/Aboutrealtimesearches

View solution in original post

0 Karma

HiroshiSatoh
Champion

It is available in the manual. Why did you think you could not do it?

Real-time searches can take advantage of all search functionality, including advanced functionality like lookups, transactions, and so on. There are also search commands that are to be used specifically in conjunction with real-time searches, such as streamstats and rtorder.

https://docs.splunk.com/Documentation/Splunk/7.1.0/Search/Aboutrealtimesearches

0 Karma

jadengoho
Builder

This is what im looking for , Thank you.

0 Karma

lloydknight
Builder
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...