<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: updating csv file periodically in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379758#M95401</link>
    <description>&lt;P&gt;I am not getting any logs or event data to update the file.&lt;BR /&gt;
The file we have is we getting that from some other external source, which contains employees details and then uploading the file in splunk and wants to update periodically&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 04:53:25 GMT</pubDate>
    <dc:creator>splunkuseradmin</dc:creator>
    <dc:date>2019-03-26T04:53:25Z</dc:date>
    <item>
      <title>updating csv file periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379756#M95399</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;

&lt;P&gt;I wanted to know what are the possible ways we can update lookup.csv file. I know,&lt;BR /&gt;
1 . through manually uploading from lookup editor and update manually edit fields using same lookup editor.&lt;/P&gt;

&lt;P&gt;I wanted to upload csv through lookup editor once, then setup a file to update every week. so that i can access from my splunk&lt;BR /&gt;
cluster and "index=collab_core".&lt;/P&gt;

&lt;P&gt;can any 1 suggest a easy or possible steps to solve this.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 23:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379756#M95399</guid>
      <dc:creator>splunkuseradmin</dc:creator>
      <dc:date>2019-03-25T23:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: updating csv file periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379757#M95400</link>
      <description>&lt;P&gt;Hi splunkuseradmin,&lt;/P&gt;

&lt;P&gt;find a detailed answer how it can be done here : &lt;A href="https://answers.splunk.com/answers/708473/how-do-you-update-a-lookup-table-manually-in-a-dis.html#answer-708607"&gt;https://answers.splunk.com/answers/708473/how-do-you-update-a-lookup-table-manually-in-a-dis.html#answer-708607&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There is also an option to use SPL in combination with &lt;CODE&gt;| inputlookup append=t ... | ... | outputlookup ...&lt;/CODE&gt; to update the lookup file using event data in Splunk itself.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 23:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379757#M95400</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-03-25T23:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: updating csv file periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379758#M95401</link>
      <description>&lt;P&gt;I am not getting any logs or event data to update the file.&lt;BR /&gt;
The file we have is we getting that from some other external source, which contains employees details and then uploading the file in splunk and wants to update periodically&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 04:53:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379758#M95401</guid>
      <dc:creator>splunkuseradmin</dc:creator>
      <dc:date>2019-03-26T04:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: updating csv file periodically</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379759#M95402</link>
      <description>&lt;P&gt;Well in this case, the easiest option is to simply replace the lookup file with the newer version on the file system of the Splunk instance itself.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 19:52:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/updating-csv-file-periodically/m-p/379759#M95402</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-03-26T19:52:02Z</dc:date>
    </item>
  </channel>
</rss>

