Add field matching rules to your lookup configuration
These attributes provide field matching rules for lookups. They can be applied to all three lookup types. Add them to the
transforms.conf stanza for your lookup.
||Integer|| The maximum number of possible matches for each value input to the lookup table from your events. Range is 1-1000. If the
|| 1000 if the |
||Integer|| The minimum number of possible matches for each value input to the lookup table from your events. You can use
||0 for both non-time-bounded lookups and time-bounded lookups, which means nothing is output to your event if no match is found.|
||Boolean|| Specify true to consider case when matching lookup table fields, false to ignore case.
Note: You do not need to set this attribute for KV store lookups. KV store lookups are always case sensitive .
||String|| Allows non-exact matching of one or more fields arranged in a list delimited by a comma followed by a space. Format is
Configure geospatial lookups
Configure a time-based lookup
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.5.0, 6.5.1, 6.5.2, 6.5.3