<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to install lookup app in Free Splunk Version? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549283#M155846</link>
    <description>&lt;P&gt;Thanks for the information. I will read up on it. What I actually needed to get was the Lookup Editor App which worked like a charm... Here is the link for the app:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/1724/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/1724/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Apr 2021 22:27:15 GMT</pubDate>
    <dc:creator>MeMilo09</dc:creator>
    <dc:date>2021-04-25T22:27:15Z</dc:date>
    <item>
      <title>How to install lookup app in Free Splunk Version?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549180#M155801</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have installed the free Splunk version. I am trying to upload lookups, but I don't seem to have that capability. I have downloaded&amp;nbsp;&lt;SPAN&gt;"CVE Lookup - By Fuzzmymind.com" app, but cant use it because&amp;nbsp;its asking&amp;nbsp; me to fill the below... I don't&amp;nbsp;what these fields mean. Anybody out there know?&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MeMilo09_0-1619204650370.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13913iAAAD785AC2AEB787/image-size/large?v=v2&amp;amp;px=999" role="button" title="MeMilo09_0-1619204650370.png" alt="MeMilo09_0-1619204650370.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 19:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549180#M155801</guid>
      <dc:creator>MeMilo09</dc:creator>
      <dc:date>2021-04-23T19:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to install lookup app in Free Splunk Version?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549198#M155809</link>
      <description>&lt;P&gt;This view comes from the setup.xml that is shipped with the app.&amp;nbsp;The author is asking you to set the index, interval, and disabled attributes for the scripted input they have packaged with this app.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;block title="Configure the scripted input" endpoint="data/inputs/script" entity=".%252Fbin%252Fmain.py"&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;See the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTinput#data.2Finputs.2Fscript.2F.7Bname.7D" target="_self"&gt;data/inputs/script documentation in the REST reference guide&lt;/A&gt;&amp;nbsp;or the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/inputsconf#Scripted_Input:" target="_self"&gt;inputs.conf.spec file in the docs&lt;/A&gt; about what these parameters mean. (you may also check out the inputs.conf file and the python script that are shipped with the app by default).&lt;BR /&gt;&lt;BR /&gt;(Giving a quick glance at the main.py script... this app is hardcoded to retrieve the 3 years that it retrieves, and does no checkpointing (there's , so you'll wind up with duplicates if you run it more than once, but the &lt;A href="https://nvd.nist.gov/vuln/data-feeds#JSON_FEED" target="_self"&gt;feeds that it's pulling&lt;/A&gt; can be updated once a day... The author seemed to also want to cut out the&amp;nbsp;configurations information from each vulnerability as well. Guess it depends on your use case for the data.)&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 22:22:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549198#M155809</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2021-04-23T22:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to install lookup app in Free Splunk Version?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549283#M155846</link>
      <description>&lt;P&gt;Thanks for the information. I will read up on it. What I actually needed to get was the Lookup Editor App which worked like a charm... Here is the link for the app:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/1724/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/1724/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 22:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-install-lookup-app-in-Free-Splunk-Version/m-p/549283#M155846</guid>
      <dc:creator>MeMilo09</dc:creator>
      <dc:date>2021-04-25T22:27:15Z</dc:date>
    </item>
  </channel>
</rss>

