Suppose i have a lookup with two fields input and output.
Initial,Final
abc*,abc
def*,def
so anything matches with abc* should give abc as output. Similarly anything matches with def* should give def as output.
Added csv file in lookups file of particular app.
Created transforms.conf in local folder and added below lines.
[abc]
filename = abc.csv
I m not getting anything with the below query.
index=* sourcetype=* | lookup abc Initial OUTPUT Final
Thanks in advance
Thanks Michaelis... got the answer
Luckily someone else had the exact same question: https://answers.splunk.com/answers/52580/can-we-use-wildcard-characters-in-a-lookup-table.html