Let me be more clear: I have defined a lookup file (ip_lookup) which has two colums: IPHost and DNShost
Now I have a search which has two fields, src_ip and dest_ip. I successfully created a new field by using lookup like this:
index=fw_cisco | lookup ip_lookup IPHost as src_ip OUTPUT DNShost as resolved_source_ip
But I want to do the same for the field dest_ip too. Doing lookup like this: | lookup ip_lookup IPHost as src_ip, dest_ip ... throws an error
How do I create two new fields that match the src_ip and dest_ip of my events, from the same lookup command
Try something like this
index=fw_cisco | lookup ip_lookup IPHost as src_ip OUTPUT DNShost as resolved_source_ip | lookup ip_lookup IPHost as dst_ip OUTPUT DNShost as resolved_destination_ip
Try something like this
index=fw_cisco | lookup ip_lookup IPHost as src_ip OUTPUT DNShost as resolved_source_ip | lookup ip_lookup IPHost as dst_ip OUTPUT DNShost as resolved_destination_ip
thanks that worked
is there a way to do it with one lookup command?
Not for what you are trying to do - you can use multiple lookup fields but they would both have to match rows in the lookup file at the same time i.e. there would need to be both source and destination columns in your lookup file