<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Input Lookup:  Compare previous version of input lookup to current version using SPL in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682295#M11943</link>
    <description>&lt;P&gt;The simple answer is no - however, you could include a version number in your lookup, or a modified date as a new field, or every time you update it you save the old copy to a different lookup. Essentially, Splunk can only find information that you choose to keep.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2024 15:31:49 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-03-28T15:31:49Z</dc:date>
    <item>
      <title>Input Lookup:  Compare previous version of input lookup to current version using SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682286#M11942</link>
      <description>&lt;P&gt;Is there currently a capability in Splunk that will allow us search and compare the previous version of an input lookup to the current version of the input lookup to identify what has changed between the two?&amp;nbsp; In search is there a parameter we can pass the&amp;nbsp; input lookup command to specify the version what we want to evaluate?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 14:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682286#M11942</guid>
      <dc:creator>regarza</dc:creator>
      <dc:date>2024-03-28T14:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Input Lookup:  Compare previous version of input lookup to current version using SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682295#M11943</link>
      <description>&lt;P&gt;The simple answer is no - however, you could include a version number in your lookup, or a modified date as a new field, or every time you update it you save the old copy to a different lookup. Essentially, Splunk can only find information that you choose to keep.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 15:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682295#M11943</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-28T15:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Input Lookup:  Compare previous version of input lookup to current version using SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682326#M11945</link>
      <description>&lt;P&gt;Thanks for commenting on my scenario, that is the same conclusion that I came to, but was hoping to find a way around it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 18:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682326#M11945</guid>
      <dc:creator>regarza</dc:creator>
      <dc:date>2024-03-28T18:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Input Lookup:  Compare previous version of input lookup to current version using SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682472#M11951</link>
      <description>&lt;P&gt;Another walkaround is to collect the lookup data to an index before overwriting it with another "release". Then you can do a normal search against your indexed data.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2024 09:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Input-Lookup-Compare-previous-version-of-input-lookup-to-current/m-p/682472#M11951</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-03-30T09:08:53Z</dc:date>
    </item>
  </channel>
</rss>

