<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to set up a Splunk DB Connect 2 Lookup that is available in the Search App? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204746#M21697</link>
    <description>&lt;P&gt;I am using DB Connect 2 to pull information from database into a lookup table.  It is setup correctly but the lookup table is not available in Search app.  It looks like it is only available under the DB Connect App.  What do I have to do to make it available globally?  I found the lookup definition created by  DB Connect and changed the permission to global but I still get the following error when I try to use the lookup table in Search App:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'lookup' command: The lookup table 'db_connect_CarrierLookup' does not exist. 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If I run the exact search under DB Connect V2 app it works.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2015 18:57:28 GMT</pubDate>
    <dc:creator>bshamsian</dc:creator>
    <dc:date>2015-09-03T18:57:28Z</dc:date>
    <item>
      <title>How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204746#M21697</link>
      <description>&lt;P&gt;I am using DB Connect 2 to pull information from database into a lookup table.  It is setup correctly but the lookup table is not available in Search app.  It looks like it is only available under the DB Connect App.  What do I have to do to make it available globally?  I found the lookup definition created by  DB Connect and changed the permission to global but I still get the following error when I try to use the lookup table in Search App:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'lookup' command: The lookup table 'db_connect_CarrierLookup' does not exist. 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If I run the exact search under DB Connect V2 app it works.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 18:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204746#M21697</guid>
      <dc:creator>bshamsian</dc:creator>
      <dc:date>2015-09-03T18:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204747#M21698</link>
      <description>&lt;P&gt;DB Connect looks more and more useless every time I try to use it.   I had issues before with using DB Connect with outputting data from Splunk - now it looks like lookup using DB Connect is also useless.  &lt;/P&gt;

&lt;P&gt;According to Splunk Support any data pulled into Splunk using DB Lookup is only available while you are in the DB Connect App context so Lookup tables created by DB Lookup are not available to be used ins searches or alerts or dashboards outside of DB Connect App.&lt;/P&gt;

&lt;P&gt;How useless is this feature.  If I am importing data using DB Connect to a lookup table it should be obvious that I want to use it in Search App or a dashboard I created under Search App or an alert I setup.  What use is it to anyone if it can only be seen under the DB Connect App.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 18:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204747#M21698</guid>
      <dc:creator>bshamsian</dc:creator>
      <dc:date>2015-09-04T18:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204748#M21699</link>
      <description>&lt;P&gt;Try these steps&lt;/P&gt;

&lt;P&gt;1) Go to Settings-&amp;gt;Lookups -&amp;gt;  Lookup table files, change the App context to DB Connect and locate your lookup table.&lt;BR /&gt;
2) In the right most column Actions, click on Move for the record of your lookup table and select Search as application and click on Move.&lt;BR /&gt;
3) You can see the object moved to Search apps and App context is changed to Search. Optionally, you can change it's Sharing to All apps (by clicking on Permissions under Sharing column).&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 18:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204748#M21699</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-09-04T18:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204749#M21700</link>
      <description>&lt;P&gt;That is the problem - The tables that are created dynamically are not listed there under Lookup Table Files.  It is hidden and I have no access to it to change the permission.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2015 19:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204749#M21700</guid>
      <dc:creator>bshamsian</dc:creator>
      <dc:date>2015-09-04T19:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204750#M21701</link>
      <description>&lt;P&gt;please try adding these to the local.meta file. this should resolve the issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[transforms]
export = system

[searchscripts]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 05 Oct 2015 20:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204750#M21701</guid>
      <dc:creator>jcoates_splunk</dc:creator>
      <dc:date>2015-10-05T20:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204751#M21702</link>
      <description>&lt;P&gt;into which of the local.meta files?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 12:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204751#M21702</guid>
      <dc:creator>hgehrts_splunk</dc:creator>
      <dc:date>2015-10-13T12:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204752#M21703</link>
      <description>&lt;P&gt;Same question as above that which local.meta file are you talking about?  If you are talking about the user local.meta then I have to note that we are using LDAP and have lots of users and cannot really go and create local.meta for each user.  There really should be a better solution for this.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 19:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204752#M21703</guid>
      <dc:creator>bshamsian</dc:creator>
      <dc:date>2015-11-05T19:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up a Splunk DB Connect 2 Lookup that is available in the Search App?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204753#M21704</link>
      <description>&lt;P&gt;Okay, thanks in part to &lt;A href="#314784"&gt;the comment by&lt;/A&gt; @jcoates, I was able to get it working.&lt;/P&gt;

&lt;P&gt;There are 3 components of a DB lookup (4 for automatic lookups):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;dblookup.py&lt;/CODE&gt; (the python script which does the heavy lifting)&lt;/LI&gt;
&lt;LI&gt;a &lt;STRONG&gt;lookup definition&lt;/STRONG&gt; defined in transforms.conf&lt;/LI&gt;
&lt;LI&gt;a &lt;STRONG&gt;lookup input&lt;/STRONG&gt; defined in inputs.conf&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In order to get DB lookups defined in other apps to work, you need (at minimum):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;dblookup.py&lt;/CODE&gt; exported globally&lt;/LI&gt;
&lt;LI&gt;your &lt;STRONG&gt;lookup definition&lt;/STRONG&gt; exported globally&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Here's how I did it.&lt;/P&gt;

&lt;H4&gt;Export &lt;CODE&gt;dblookup.py&lt;/CODE&gt; globally&lt;/H4&gt;

&lt;P&gt;Add the following stanza to &lt;CODE&gt;$SPLUNK_HOME/etc/apps/splunk_app_db_connect/metadata/local.meta&lt;/CODE&gt; to export the &lt;CODE&gt;dblookup.py&lt;/CODE&gt; script globally (I couldn't figure out a way to do this via the web interface)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[searchscripts/dblookup.py]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(At this point, I restarted Splunk)&lt;/P&gt;

&lt;H4&gt;Define your DB lookup&lt;/H4&gt;

&lt;P&gt;I used the GUI and selected the app context at the end of the wizard. If you've defined it in the wrong place, you should move the lookup definition via the DB Connect app instead of via the normal Splunk settings page (e.g. edit the config and change the app context), because there's also an input that needs to be moved.&lt;/P&gt;

&lt;P&gt;Defining the DB lookup will create the following:&lt;/P&gt;

&lt;P&gt;in &lt;CODE&gt;$SPLUNK_HOME/etc/apps//local/transforms.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[&amp;lt;lookup name&amp;gt;]
external_cmd = dblookup.py &amp;lt;lookup name&amp;gt;
fields_list = &amp;lt;comma-separated list of fields you've defined&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in &lt;CODE&gt;$SPLUNK_HOME/etc/apps//local/inputs.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[mi_lookup://&amp;lt;lookup name&amp;gt;]
... # there's about 16 entries under this stanza. It contains the raw SQL for the lookup, as well as some other bits and pieces used by the gui
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In &lt;CODE&gt;$SPLUNK_HOME/etc/apps//metadata/local.meta&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[transforms/&amp;lt;lookup name&amp;gt;]
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you've defined the lookup as an automatic lookup, you'll also have entries in &lt;CODE&gt;$SPLUNK_HOME/etc/apps//local/props.conf&lt;/CODE&gt; like so:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[&amp;lt;spec&amp;gt;]
LOOKUP-db_connect_&amp;lt;lookup name&amp;gt; = &amp;lt;lookup name&amp;gt; &amp;lt;field&amp;gt; AS &amp;lt;alias&amp;gt; OUTPUTNEW &amp;lt;field&amp;gt;...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and in &lt;CODE&gt;$SPLUNK_HOME/etc/apps//metadata/local.meta&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[props/&amp;lt;props_spec&amp;gt;/LOOKUP-db_connect_&amp;lt;lookup name&amp;gt;]
.... # note: setting export = system here is optional. The automatic lookups will work if searches are run from within your app context.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H4&gt;Export your lookup definition globally&lt;/H4&gt;

&lt;P&gt;You can do this via the settings page in Splunk (you want the &lt;STRONG&gt;lookup definition&lt;/STRONG&gt;, not the &lt;STRONG&gt;lookup table&lt;/STRONG&gt;).&lt;/P&gt;

&lt;P&gt;Alternatively, in &lt;CODE&gt;$SPLUNK_HOME/etc/apps//metadata/local.meta&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[transforms/&amp;lt;lookup name&amp;gt;]
export = system
... # other stuff already added by Splunk
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Feb 2016 08:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-set-up-a-Splunk-DB-Connect-2-Lookup-that-is-available-in/m-p/204753#M21704</guid>
      <dc:creator>steven_swor</dc:creator>
      <dc:date>2016-02-01T08:50:10Z</dc:date>
    </item>
  </channel>
</rss>

