This doesn't seem to work. Here's the way I configured it, maybe you can tell me where I went wrong.
I have two .csv files, user_lookup (referencing the first .csv) containing a column with UserID and Department . The second, department_lookup contains DivDept and DivisionDepartmentName . DivDept corresponds to values from Department and vice versa. The first lookup works, as the Department field shows up properly in my searches.
First lookup I used was:
WinEventLog:Security : LOOKUP-user_department_lookup user_lookup UserID AS Account_Name OUTPUTNEW Department AS Department
Then I set up the second lookup:
WinEventLog:Security : LOOKUP-map_dept_to_divdept department_lookup DivDept AS Department OUTPUTNEW DivisionDepartmentName AS DivDept
But no matter how I rearrange this, I can only get the first lookup to work. As it is, it doesn't throw an error, but the second lookup isn't producing any new fields. I also tried mapping the second lookup to overwrite the fields produced by the first, but that didn't work either. Suggestions?
... View more