
Overview
This three-hour course is designed for power users who want to learn how to use lookups and subsearches to enrich their results. Topics will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources.
Skills Covered
Please refer to course overview.
Prerequisites
To be successful, students should have a solid understanding of the following:
- How Splunk works
- Creating Search queries
- Lookups
Target Audience
Search Experts Knowledge Managers

Module 1: Using Lookup Commands
- Understand lookups
- Use the inputlookup command to search lookup files
- Use the lookup command to invoke field value lookups
- Invoke geospatial lookups in search
Module 2: Adding a Subsearch
- Define subsearch
- Use subsearch to filter results
- Identify when to use subsearch
- Understand subsearch limitations and alternatives
Module 3: Using the return Command
- Use the return command to pass values from a subsearch
- Compare the return and fields commands
Dates & Locations
October 26, 2026 - October 26, 2026
November 25, 2026 - November 25, 2026
February 15, 2027 - February 15, 2027
February 15, 2027 - February 15, 2027
April 5, 2027 - April 5, 2027
April 5, 2027 - April 5, 2027
June 18, 2027 - June 18, 2027
June 18, 2027 - June 18, 2027
August 3, 2027 - August 3, 2027
August 3, 2027 - August 3, 2027
October 29, 2027 - October 29, 2027
October 29, 2027 - October 29, 2027
December 17, 2027 - December 17, 2027
December 17, 2027 - December 17, 2027

Exam & Certification
This course is not associated with any Certification.
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631























