Splunk Search

Is it possible to pass dynamic field name to kvstore lookup?

Murali2888
Communicator

Hi All,
I need to lookup a value on three different kvstore fields based on its regex format. Is it possible to pass dynamic field name to kvstore lookup?

Lets say, I have three field lookup - userid, mail, secondaryids. I want to achieve something like below.
| lookup records_lookup $arg$
- where arg would be mail if value is of email id format
- where arg would be userid if value is of aXXXXXX
- where arg would be secondaryids if value is of bXXXXXX

I am trying to avoid multiple lookup statements into my search as the lookup value can only be of one format.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...