A knowledge object that provides data enrichment by mapping a select value in an event to a field in another data source, and appending the matched results to the original event. For example, you can use a lookup to match an HTTP status code and return a new field containing a detailed description of the status. The data sources for lookup content include search results, .csv files, a KVStore collection, or a database connection.

Lookups are incorporated into dashboards and forms to provide content in a human readable format, allowing users to interact with event data without knowing obscure or cryptic event fields.

For more information

In the Knowledge Manager Manual:

In the Developing Views and Apps for Splunk Web: