Overview

This three-hour course is designed for power users who want to learn how to use lookups and subsearches to enrich their results. Topics will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources.

Skills Covered

Please refer to course overview.

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk works
  • Creating Search queries
  • Lookups

Target Audience

Search Experts Knowledge Managers

Course Curriculum

Module 1: Using Lookup Commands

  • Understand lookups
  • Use the inputlookup command to search lookup files
  • Use the lookup command to invoke field value lookups
  • Invoke geospatial lookups in search

Module 2: Adding a Subsearch

  • Define subsearch
  • Use subsearch to filter results
  • Identify when to use subsearch
  • Understand subsearch limitations and alternatives

Module 3: Using the return Command

  • Use the return command to pass values from a subsearch
  • Compare the return and fields commands

Dates & Locations

Let’s make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our learning experts today.

July 27, 2026 - July 27, 2026

Location: Online
Modal: VILT
Availability: TBC

September 21, 2026 - September 21, 2026

Location: Online
Modal: VILT
Availability: TBC
Trainocate exam and cert

Exam & Certification

This course is not associated with any Certification.

Training & Certification Guide

Frequently Asked Questions

Speak to a Training Consultant

All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631

Preferred mode of training
Checkboxes