Splunk Search

Lookup Definition - Default Matches not working as expected

jackreeves
Explorer

Hi,

I have built a lookup table, definition & automatic lookup.

I've set the definition to;
Min Matches - 1
Max Matches - 1
Default Matches - None

The additional lookup fields appear in the appear data as expected with 1 result having the value of "None". However, when I click the "None" value it appears as no results found. If I then add a wildcard value before the "*None", the one result in question appears.

Has anyone else come across same issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...