This section lists several important Splunk commands you will use when working with lookups.
The lookup command
lookup command is used to manually invoke field lookups using a Splunk lookup table that is previously defined. You can use Splunk Web (or the
transforms.conf file) to define your lookups.
If you do not specify
OUTPUTNEW, all fields in the lookup table (excluding the lookup match field) will be used by Splunk as output fields. Conversely, if
OUTPUT is specified, the output lookup fields will overwrite existing fields and if
OUTPUTNEW is specified, the lookup will not be performed for events in which the output fields already exist.
For example, if you have a lookup table specified as
iptousername with ...