Leveraging Lookups and Subsearches

This three-hour module is designed for power users who want to learn how to use lookups and subsearches to enrich their results. Topics will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources.

Days : 1
Price :

This product is currently out of stock and unavailable.


This course is part of the following Certifications:

Splunk Core Certified Advanced Power User
Splunk Core Certified User


To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Knowledge objects
  • Lookups

Course Objectives

  • Using Lookup Commands
  • Adding a Subsearch
  • Using the return Command

Outline: Leveraging Lookups and Subsearches (LLS)

Topic 1 – Using Lookup Commands

  • Understand lookups
  • Use the inputlookup command to search lookup files
  • Use the lookup command to invoke field value lookups
  • Use the outputlookup command to create lookups
  • Invoke geospatial lookups in search

Topic 2 – Adding a Subsearch

  • Define subsearch
  • Use subsearch to filter results
  • Identify when to use subsearch
  • Understand subsearch limitations and alternatives

Topic 3 – Using the return Command

  • Use the return command to pass values from a subsearch
  • Compare the return and fields commands