<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upload/update lookup file using rest API in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755548#M23476</link>
    <description>&lt;P&gt;Have a look at this solution&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Can-you-create-modify-a-lookup-file-via-REST-API/m-p/193699" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Can-you-create-modify-a-lookup-file-via-REST-API/m-p/193699&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252465"&gt;@mthcht&lt;/a&gt;&amp;nbsp;wrote a script that works. I modified it a little for my use but it is basically the same solution and works on a single head or on a SHC. The gist is that i&lt;SPAN&gt;t loops through and reads the contents in python and then uploads a big string.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Nov 2025 07:24:36 GMT</pubDate>
    <dc:creator>burwell</dc:creator>
    <dc:date>2025-11-16T07:24:36Z</dc:date>
    <item>
      <title>Upload/update lookup file using rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755509#M23471</link>
      <description>&lt;P&gt;What is the recommended way to upload / update an existing lookup file through rest api.&lt;/P&gt;&lt;P&gt;I tried using lookup endpoints but it doesnt seem to be working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/9.2/knowledge-endpoints/knowledge-endpoint-descriptions#id_888abd9e_5010_410e_a424_7384a9f13269__data.2Flookup-table-files" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/9.2/knowledge-endpoints/knowledge-endpoint-descriptions#id_888abd9e_5010_410e_a424_7384a9f13269__data.2Flookup-table-files&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In short, I have a lookup file, abc.csv in search application under my ownership. I now need to overwrite with an updated file. How can we do this using rest api?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 11:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755509#M23471</guid>
      <dc:creator>jpillai</dc:creator>
      <dc:date>2025-11-14T11:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Upload/update lookup file using rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755544#M23475</link>
      <description>&lt;P&gt;Well... this is tricky because the endpoints for lookup table files require you to first upload the file to the server using another channel. Then with API you point Splunk to such file and it copies the file into its own directory.&lt;/P&gt;&lt;P&gt;You can't directly upload a lookup file into Splunk.&lt;/P&gt;&lt;P&gt;If I&amp;nbsp; remember correctly, the lookup editor app had API which allowed for overwriting lookups directly but they might not be documented.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Nov 2025 14:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755544#M23475</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-15T14:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Upload/update lookup file using rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755548#M23476</link>
      <description>&lt;P&gt;Have a look at this solution&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Can-you-create-modify-a-lookup-file-via-REST-API/m-p/193699" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Can-you-create-modify-a-lookup-file-via-REST-API/m-p/193699&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252465"&gt;@mthcht&lt;/a&gt;&amp;nbsp;wrote a script that works. I modified it a little for my use but it is basically the same solution and works on a single head or on a SHC. The gist is that i&lt;SPAN&gt;t loops through and reads the contents in python and then uploads a big string.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Nov 2025 07:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Upload-update-lookup-file-using-rest-API/m-p/755548#M23476</guid>
      <dc:creator>burwell</dc:creator>
      <dc:date>2025-11-16T07:24:36Z</dc:date>
    </item>
  </channel>
</rss>

