Lookup
Outside non-event data added to an index to provide supporting info/context
(Dataset)
Two steps to setup a lookup
Upload lookup file (CSV)
Define lookup type
Lookup command
inputlookup
Lookups are assigned to which apps?
Only the one imported to or with permissions.
Output clause
Choose which fields lookup returns
(New fields)
outputnew clause
Prevents overwriting existing fields
inputlookup command
Load results from static lookup
Works on file and imported definition {values}
Time-based lookups
Can be created if a field contains a timestamp