Hello,
I have a lookup file which contains field and it’s values as follow.
Country location
India Andhra Pradesh
Himachal Pradesh
Madhya Pradesh
USA San Fransisco
San Andrea
Illinois
China Beijing
Jiangsu
Anhui
I have a query which gives the results as follow.
India Andhra Pradesh
India Madhya Pradesh
USA San Fransisco
China Beijing
China Anhui
I would like to filter out the one’s which are missing in the results and present in the lookup file.
Expected output:
India Himachal Pradesh
USA San Andrea
USA Illinois
China Anhui
Review these slides for the part about sentinel lookups
https://conf.splunk.com/session/2015/conf2015-LookupTalk.pdf