<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to update a lookup file in Splunk from Phantom? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600381#M208995</link>
    <description>&lt;P&gt;That did also not work for the same permission related reasons, but like I said it's working now.&lt;/P&gt;&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2022 05:08:34 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2022-06-03T05:08:34Z</dc:date>
    <item>
      <title>How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/552038#M156663</link>
      <description>&lt;P&gt;How to update a lookup file in splunk from Phantom?&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/552038#M156663</guid>
      <dc:creator>yadavameeth</dc:creator>
      <dc:date>2021-05-18T12:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/597863#M208182</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;we encountered the exact same problem. Using the provided commands in the Splunk app in Phantom it seems there is no way to update a lookup table BUT we have a workaround for that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; If you are forwarding the Phantom event to Splunk you can use those events and run a scheduled search that will then update the lookup file.&lt;/P&gt;&lt;P&gt;Hope this helps ...&lt;/P&gt;&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Sun, 15 May 2022 00:47:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/597863#M208182</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2022-05-15T00:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600254#M208963</link>
      <description>&lt;P&gt;Okay, found the solution!&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not documented anywhere but the lookup definition in Splunk needs to be shared globally AND the owner of the lookup definition needs to be 'nobody' - also remember to set the permission of the CSV so everyone is able to write and share it globally as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps ...&lt;/P&gt;&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 10:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600254#M208963</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2022-06-02T10:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600274#M208965</link>
      <description>&lt;P&gt;You could also simply call REST API to update lookup contents.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 12:13:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600274#M208965</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-02T12:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600381#M208995</link>
      <description>&lt;P&gt;That did also not work for the same permission related reasons, but like I said it's working now.&lt;/P&gt;&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 05:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/600381#M208995</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2022-06-03T05:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to update a lookup file in Splunk from Phantom?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/625336#M217378</link>
      <description>&lt;P&gt;Hi i made &lt;A href="https://github.com/mthcht/lookup-editor_scripts#readme." target="_self"&gt;these scripts&lt;/A&gt; to update or upload lookups on splunk using lookup-editor endpoint&amp;nbsp;&lt;/P&gt;&lt;P&gt;It can save the content of lookup(s) from splunk, add new fields and values or merge files and update them on splunk, you can use them in your playbooks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 15:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-update-a-lookup-file-in-Splunk-from-Phantom/m-p/625336#M217378</guid>
      <dc:creator>mthcht</dc:creator>
      <dc:date>2022-12-27T15:19:56Z</dc:date>
    </item>
  </channel>
</rss>

