Currently in my logs I am getting the hostname of the users but not their usernames. I created a lookup table that contains hostnames and usernames. I am trying to match the hostname from search to the hostname in the lookup file and then print their correlated username in a table format in the search visualization. Lookup file: hostname username host1 user1 host2 user2 host3 user3 host4 user4 search: index=windows sourcetype:eventlogs [|inputlookup users.csv | fields hostname username | rename hostname as users] ~~~print username correlated to "users" in the above string.~~~
... View more