<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121987#M7659</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have a lookup file which changes frequently. Currently, we are have a base csv file physically on the server. Any changes are made to the server copy of csv file and then the update CSV file is uploaded to Splunk as lookup table, so that lookup file always have current data.&lt;BR /&gt;
The drawback of this is that I can't keep track of changes within splunk ( I can log them in a file but that's an overhead.&lt;BR /&gt;
Lookup file format&lt;BR /&gt;
field1,field2,field3&lt;/P&gt;

&lt;P&gt;The solution that I was trying was this&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Add history related fields like changed_date, changed_by in the base CSV file&lt;/P&gt;

&lt;P&gt;changed_date,field1,field2,field3,changed_by&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Add this base CSV file as lookup table file in another app (say MgmtApp).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Have Splunk monitor this base CSV lookup file in the MgmtApp in an index, say lookupHistory.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Use "Sideview Util -The Lookup Updater" to add/update data (data is not deleted) in base CSV lookup file. All changes (add/updated) should go to lookupHistory index with updated timestamp.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Use a scheduled search to take latest value of field1,field2,field3 combination and use outputlookup command to generate actualy lookup file in another app (say MainApp).&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;In theory this approach looked fine as I was having history data and a way to have latest lookup file will less manualy intervention. But the problem that I am facing is that, everytime I add/update a row using the "Lookup Updater" view, Splunk is re-indexing whole base CSV file (say initial event count in index=lookupHistory is 50, I add a new row, total event count in becomes 101, if I update a value now, it becomes 152).&lt;/P&gt;

&lt;P&gt;Is there a way to instruct Splunk to just index new/updated data and not to re-index whole file?&lt;BR /&gt;
Or If you have any suggestion to what I am trying to achieve, that will be appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:41:59 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2020-09-28T15:41:59Z</dc:date>
    <item>
      <title>Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121987#M7659</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have a lookup file which changes frequently. Currently, we are have a base csv file physically on the server. Any changes are made to the server copy of csv file and then the update CSV file is uploaded to Splunk as lookup table, so that lookup file always have current data.&lt;BR /&gt;
The drawback of this is that I can't keep track of changes within splunk ( I can log them in a file but that's an overhead.&lt;BR /&gt;
Lookup file format&lt;BR /&gt;
field1,field2,field3&lt;/P&gt;

&lt;P&gt;The solution that I was trying was this&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Add history related fields like changed_date, changed_by in the base CSV file&lt;/P&gt;

&lt;P&gt;changed_date,field1,field2,field3,changed_by&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Add this base CSV file as lookup table file in another app (say MgmtApp).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Have Splunk monitor this base CSV lookup file in the MgmtApp in an index, say lookupHistory.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Use "Sideview Util -The Lookup Updater" to add/update data (data is not deleted) in base CSV lookup file. All changes (add/updated) should go to lookupHistory index with updated timestamp.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Use a scheduled search to take latest value of field1,field2,field3 combination and use outputlookup command to generate actualy lookup file in another app (say MainApp).&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;In theory this approach looked fine as I was having history data and a way to have latest lookup file will less manualy intervention. But the problem that I am facing is that, everytime I add/update a row using the "Lookup Updater" view, Splunk is re-indexing whole base CSV file (say initial event count in index=lookupHistory is 50, I add a new row, total event count in becomes 101, if I update a value now, it becomes 152).&lt;/P&gt;

&lt;P&gt;Is there a way to instruct Splunk to just index new/updated data and not to re-index whole file?&lt;BR /&gt;
Or If you have any suggestion to what I am trying to achieve, that will be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121987#M7659</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-28T15:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121988#M7660</link>
      <description>&lt;P&gt;Who updates the lookup file?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 17:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121988#M7660</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-01-22T17:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121989#M7661</link>
      <description>&lt;P&gt;Its a file which holds today's rate and updated daily by users with admin role. I have 6 such files&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 17:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121989#M7661</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-01-22T17:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121990#M7662</link>
      <description>&lt;P&gt;Can't you use outputlookup and keep all the records rather than updating it? index and Dedup all the records to get the latest record. But you need to add new columns  you specified to keep track of them..&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 18:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121990#M7662</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-01-22T18:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121991#M7663</link>
      <description>&lt;P&gt;The values to be updated manually in the base CSV file (that's the reason I was tried Lookup Updater so that updates can be done from UI instead of manual file change and upload to SPlunk Server). Another option (I guess you're suggesting the same) is to index the base CSV file and next time just keep indexing new changes (instead of monitoring of file it will be one time indexing for every change) and than write a search to get latest values into lookup (using outputlookup command). But this still left me with manual change of file, copying file to Splunk Server and indexing it manually.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 19:18:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121991#M7663</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-01-22T19:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121992#M7664</link>
      <description>&lt;P&gt;Am I right in thinking that the core requirement here is auditability/visibility of admin changes to the lookup?  That you need to know who changes the lookup when and how? &lt;BR /&gt;
It sounds like a good general feature that the Lookup Updater is currently lacking.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2014 19:13:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121992#M7664</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2014-03-04T19:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121993#M7665</link>
      <description>&lt;P&gt;You got it right on the money &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
The lookup updater itself was a very good tool, having this fearue (storing history) will make it pretty useful.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2014 20:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121993#M7665</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-03-04T20:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121994#M7666</link>
      <description>&lt;P&gt;Alright. Yes in hindsight it's a huge feature that was missing.  I'll add something to my queue to log changes.  Probably via its own standalone log in /var/log/splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2014 20:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121994#M7666</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2014-03-04T20:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring lookup file, adding duplicate records - Sideview Utils The lookup Updater</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121995#M7667</link>
      <description>&lt;P&gt;Thanks. awaiting your new release.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 21:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-lookup-file-adding-duplicate-records-Sideview-Utils/m-p/121995#M7667</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-03-06T21:46:50Z</dc:date>
    </item>
  </channel>
</rss>

