Hello @Rushit Ajudiya
- ipv4_lookup plugin is the nearest equivalent to iplocation, though there isn't a built in table for IP locations, giving you the flexibility to choose the example table or from another provider. Also note, that some logs, such as Azure AD Sign in logs are already enriched with IP location information. Also IP addresses mapped to entities and Threat Intelligence IP's are also enriched with geolocation data.
- There is no KQL equivalent to lookup as KQL is a read only language within Log Analytics and therefore doesn't add any new data to the environment. To perform something similar, you would need to ingest data to the environment and perform a join. Ways that you can do this include
- Watchlists
- Threat Intelligence
- Playbook or equivalent method for ingesting data to log analytics
- externaldata() operator
- distinct is the operator I believe you want for values()