{"course":{"productid":26165,"modality":1,"active":true,"language":"fr","title":"Leveraging Lookups and Subsearches","productcode":"LLS","vendorcode":"SP","vendorname":"Splunk","fullproductcode":"SP-LLS","courseware":{"has_ekit":false,"has_printkit":true,"language":""},"url":"https:\/\/portal.flane.ch\/course\/splunk-lls","essentials":"<p>To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:\n<\/p>\n<ul>\n<li>Intro to Splunk<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-suf\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Using Fields <span class=\"fl-prod-pcode\">(SUF)<\/span><\/a><\/span><\/li><li>Visualizations<\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-wwt\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Working with Time <span class=\"fl-prod-pcode\">(WWT)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-ssp\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Statistical Processing <span class=\"fl-prod-pcode\">(SSP)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-scv\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Comparing Values <span class=\"fl-prod-pcode\">(SCV)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-srm\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Result Modification <span class=\"fl-prod-pcode\">(SRM)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/product\/splunk-sra\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Scheduling Reports & Alerts <span class=\"fl-prod-pcode\">(SRA)<\/span><\/a><\/span><\/li><li><span class=\"cms-link-marked\"><a class=\"fl-href-prod\" href=\"\/swisscom\/fr\/course\/splunk-itd\"><svg role=\"img\" aria-hidden=\"true\" focusable=\"false\" data-nosnippet class=\"cms-linkmark\"><use xlink:href=\"\/css\/img\/icnset-linkmarks.svg#linkmark\"><\/use><\/svg>Introduction to Dashboards <span class=\"fl-prod-pcode\">(ITD)<\/span><\/a><\/span><\/li><\/ul>","audience":"<ul>\n<li>Users\/Analysts<\/li><li>Administrators<\/li><li>Engineers<\/li><\/ul>","outline":"<p><strong>Module 1 &ndash; Using Lookup Commands<\/strong><\/p>\n<ul>\n<li>Understand lookups<\/li><li>Use the inputlookup command to search lookup files<\/li><li>Use the lookup command to invoke field value lookups<\/li><li>Use the outputlookup command to create lookups<\/li><li>Invoke geospatial lookups in search<\/li><\/ul><p><strong>Module 2 &ndash; Adding a Subsearch<\/strong><\/p>\n<ul>\n<li>Define subsearch<\/li><li>Use subsearch to filter results<\/li><li>Identify when to use subsearch<\/li><li>Understand subsearch limitations and alternatives<\/li><\/ul><p><strong>Module 3 &ndash; Using the return Command<\/strong><\/p>\n<ul>\n<li>Use the return command to pass values from a subsearch<\/li><li>Compare the return and fields commands<\/li><\/ul>","summary":"<p>This course is designed for Splunk users, analysts, and administrators who want to enhance their searches with lookups and subsearches.\nYou will learn how to use lookups to enrich your data and how to write subsearches to correlate and filter data from multiple sources.<\/p>","essentials_plain":"To be successful, students must have completed these Splunk Education course(s) or have equivalent working knowledge:\n\n\n\n- Intro to Splunk\n- Using Fields (SUF)\n- Visualizations\n- Working with Time (WWT)\n- Statistical Processing (SSP)\n- Comparing Values (SCV)\n- Result Modification (SRM)\n- Scheduling Reports & Alerts (SRA)\n- Introduction to Dashboards (ITD)","audience_plain":"- Users\/Analysts\n- Administrators\n- Engineers","outline_plain":"Module 1 \u2013 Using Lookup Commands\n\n\n- Understand lookups\n- Use the inputlookup command to search lookup files\n- Use the lookup command to invoke field value lookups\n- Use the outputlookup command to create lookups\n- Invoke geospatial lookups in search\nModule 2 \u2013 Adding a Subsearch\n\n\n- Define subsearch\n- Use subsearch to filter results\n- Identify when to use subsearch\n- Understand subsearch limitations and alternatives\nModule 3 \u2013 Using the return Command\n\n\n- Use the return command to pass values from a subsearch\n- Compare the return and fields commands","summary_plain":"This course is designed for Splunk users, analysts, and administrators who want to enhance their searches with lookups and subsearches.\nYou will learn how to use lookups to enrich your data and how to write subsearches to correlate and filter data from multiple sources.","skill_level":"Beginner","version":"1.0","duration":{"unit":"d","value":0,"formatted":"3 heures"},"pricelist":{"List Price":{"US":{"country":"US","currency":"USD","taxrate":null,"price":500},"IT":{"country":"IT","currency":"USD","taxrate":20,"price":500},"GB":{"country":"GB","currency":"GBP","taxrate":20,"price":420},"PL":{"country":"PL","currency":"USD","taxrate":23,"price":500},"DE":{"country":"DE","currency":"EUR","taxrate":19,"price":500},"CA":{"country":"CA","currency":"CAD","taxrate":null,"price":690},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":550},"NL":{"country":"NL","currency":"EUR","taxrate":21,"price":500}}},"lastchanged":"2026-02-16T12:22:37+01:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-course-schedule\/26165","source_lang":"fr","source":"https:\/\/portal.flane.ch\/swisscom\/fr\/json-course\/splunk-lls"}}