Skip to main content

outputlookup

Description

Writes search results to a table (or file).

Syntax

...| outputlookup <lookup-name>  [append=<bool>] [key_field=<bool>]

Mandatory Arguments

ParameterSyntaxDescription
lookup-name<field>The name of the predefined lookup.

Optional Arguments

ParameterSyntaxDefaultDescription
appendappend=<bool>falsetrue — appends existing data; false — ignores existing data.
key_fieldkey_field=<boolean>falsetrue — appends data matching by _id; false — appends data while ignoring _id.

Query Examples

Example #1
source radius_logs
| dedup user
| outputlookup test_lookup append=true keyfield=true
Example #2
source radius_logs
| outputlookup my_lookup