<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic lookup table in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Dynamic-lookup-table/m-p/556071#M92069</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232920"&gt;@Sangu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a solution here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40587" target="_blank"&gt;Solved: How can I upload &amp;amp; Replace lookup files on a weekl... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You need to replace the old CSV with new CSV on Splunk SH cluster/standalone. Above link having steps instead of direct replacement of file a safe approach.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 00:39:13 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-06-17T00:39:13Z</dc:date>
    <item>
      <title>Dynamic lookup table</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dynamic-lookup-table/m-p/555958#M92056</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have request to create dashboard with user information, but that user information is provided by AD team, So I need to create a lookup table to access that information. Issue is that the user information may change everyday and AD team will give new excel sheet with updated info, so how can I update the lookup table automatically,&lt;/P&gt;&lt;P&gt;Otherwise I need to upload the csv file everyday to splunk which is not best option.&lt;/P&gt;&lt;P&gt;Please give some ideas, Can we replace that file from splunk server lookup directory? does that work or any other way to do this.&lt;/P&gt;&lt;P&gt;Thanks in Advance!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 11:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dynamic-lookup-table/m-p/555958#M92056</guid>
      <dc:creator>Sangu</dc:creator>
      <dc:date>2021-06-16T11:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic lookup table</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Dynamic-lookup-table/m-p/556071#M92069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232920"&gt;@Sangu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a solution here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40587" target="_blank"&gt;Solved: How can I upload &amp;amp; Replace lookup files on a weekl... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You need to replace the old CSV with new CSV on Splunk SH cluster/standalone. Above link having steps instead of direct replacement of file a safe approach.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 00:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Dynamic-lookup-table/m-p/556071#M92069</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-17T00:39:13Z</dc:date>
    </item>
  </channel>
</rss>

