<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update lookup files in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Update-lookup-files/m-p/94571#M24404</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Lookup tables are typically stored at the search head and not the indexer. Is this an indexer &amp;amp; search head instance (i.e. doing both?)&lt;/P&gt;

&lt;P&gt;You can verify lookups from the search head by going under the Manager -&amp;gt; Lookups ad see where you file is listed and can verify the file contents by logging into the box and taking a look at that path.&lt;/P&gt;

&lt;P&gt;@Kate&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2012 19:05:13 GMT</pubDate>
    <dc:creator>Kate_Lawrence-G</dc:creator>
    <dc:date>2012-07-10T19:05:13Z</dc:date>
    <item>
      <title>Update lookup files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Update-lookup-files/m-p/94570#M24403</link>
      <description>&lt;P&gt;hi, i have already uploaded a csv lookup file to the splunk indexer. Now i want to add more entries to the csv file.  i goto the destination where it is stored on the indexer and open it and edit and save it and restart splunk. then from my web interface if i do a | input lookup &lt;FILENAME&gt; the newly added entries are not displayed. Can some one help me out??&lt;/FILENAME&gt;&lt;/P&gt;

&lt;P&gt;Thanks in Advance!!!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2012 15:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Update-lookup-files/m-p/94570#M24403</guid>
      <dc:creator>karthik7411</dc:creator>
      <dc:date>2012-07-10T15:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Update lookup files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Update-lookup-files/m-p/94571#M24404</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Lookup tables are typically stored at the search head and not the indexer. Is this an indexer &amp;amp; search head instance (i.e. doing both?)&lt;/P&gt;

&lt;P&gt;You can verify lookups from the search head by going under the Manager -&amp;gt; Lookups ad see where you file is listed and can verify the file contents by logging into the box and taking a look at that path.&lt;/P&gt;

&lt;P&gt;@Kate&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2012 19:05:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Update-lookup-files/m-p/94571#M24404</guid>
      <dc:creator>Kate_Lawrence-G</dc:creator>
      <dc:date>2012-07-10T19:05:13Z</dc:date>
    </item>
  </channel>
</rss>

