lookup

noun

A knowledge object that that enables the addtion of fields and related values to search results based on field matching with an external CSV table or Python command. For example, you can use a lookup to perform DNS or reverse DNS lookups on IP addresses or host names in your data.

Lookups can be incorporated into dashboards and other app views.

For more information

In the Knowledge Manager manual

In the Developer manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time