Thank you for the response. I did manage to figure out my issue. First was the use of the multiple lookups, when I created the first lookup, I used sort, that limited my results to > 5000, and I needed < 30k. I fixed that, creating the Inputlookup ACResults.csv without the sort value that was limiting my results. (inputlookup was from Active Directory). Then used the following search: index=Myindex host=xx.xx.xx.xx "AAA user accounting Successful" | dedup user Then used lookup for where the user field values matched the field cn from my lookup: | lookup ACResults.csv cn as user Final result of my new search: index=Myindex host=xx.xx.xx.xx "AAA user accounting Successful" | dedup user | lookup ACResults.csv cn as user | eval Sector=extensionAttribute14 | stats count by Sector | sort -count Answering your questions: -What is the relationship between the field you tabled ("user") and all the lookup tables? -user = cn from active directory -And the relationship with "field_stats_wanted"? -extensionAttribute14 for that user (cn) from Active Directory - Most importantly, why is inputlookup even considered? -all my inputlookups had the same fields, so appending would make it easier to search, (I thought), I was wrong. -It usually means that the problem is not clearly understood. - that was true, but I learned. I hope this helps for future users. Thank you all the same.
... View more