I have a lookup table that I generate as a CSV dump of one of our databases. The database contains a list of all our hostnames, the host's role (dev, prod, etc), and who it belongs to.
The lookup table matches on the host field of an event.
I have the automatic lookup table working right now, but only for a single sourcetype. It works for other sourcetypes if I manually specify the |lookup
command in the search.
Is it possible to create an automatic lookup that applies to every event, regardless of host, source, sourcetype, etc? Ideally I'd like to never have to use the |lookup
command in order to see those extra columns displayed by default.
Sure. Just use the [default]
stanza in props.conf.
[default]
LOOKUP-yourlookup = yourlookupdefinition