In the previous chapter, you continued to improve your Splunk search and analytic skills by creating more advanced searches that leveraged more of the deep analytical commands to gain more operational intelligence from the data contained within logs. In this chapter, you will leverage Splunk's lookup functionality to enrich these results with the data found outside of logs. You will also use Splunk's workflow functionality to perform some simple actions on the data that you discovered.
Introduction
Lookups
Lookups are used to enrich log data with additional data not found in the log events themselves. They allow you to key off one or more fields in the event data and add additional fields to this data. These additional...