I have a blacklist.csv file that looks like the following,
name | description |
*vpn* | VPN was found. |
*putty* | Putty was found. |
I'm trying this search and it's showing events match, but not outputting the name/description fields from the lookup.
index=os
| lookup blacklist.csv name OUTPUT description
| table name description
My goal is to search each event for every value in the name column, so the basic query I'm trying to match with the use of a lookup file is,
index=os
| search *vpn* OR *putty*
What lookup query do I need to implement this type of search and display the results?
The lookup table files (CSV lookup) doesn't support wildcard match on it's own. YOu've to create a lookup definition that supports wildcard match. Have a look at this post for more details:
What if there's no specific field I'm trying to search on?