
Overview
This three-hour course is designed for power users who want to learn how to use lookups and subsearches to enrich their results. Topics will focus on lookup commands and explore how to use subsearches to correlate and filter data from multiple sources.
Skills Covered
Please refer to course overview.
Prerequisites
To be successful, students should have a solid understanding of the following:
- How Splunk works
- Creating Search queries
- Lookups
Target Audience
Search Experts Knowledge Managers

Module 1: Using Lookup Commands
- Understand lookups
- Use the inputlookup command to search lookup files
- Use the lookup command to invoke field value lookups
- Invoke geospatial lookups in search
Module 2: Adding a Subsearch
- Define subsearch
- Use subsearch to filter results
- Identify when to use subsearch
- Understand subsearch limitations and alternatives
Module 3: Using the return Command
- Use the return command to pass values from a subsearch
- Compare the return and fields commands
Dates & Locations
July 27, 2026 - July 27, 2026
September 21, 2026 - September 21, 2026

Exam & Certification
This course is not associated with any Certification.
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631























