<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are my additional columns in my asset lookup not showing in Splunk Web? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208986#M61034</link>
    <description>&lt;P&gt;I have resolved my own issue.  These additional columns came after I initially implemented the asset lookup table.  I needed to reload apps from my deployment server to the search heads to get the latest data.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2016 18:01:16 GMT</pubDate>
    <dc:creator>darlas</dc:creator>
    <dc:date>2016-02-19T18:01:16Z</dc:date>
    <item>
      <title>Why are my additional columns in my asset lookup not showing in Splunk Web?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208983#M61031</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I have added a few additional columns to my asset lookup CSV, meaning in addition to the required columns.  When I validate the content of the lookup, I see only the required columns and not my additional columns.&lt;/P&gt;

&lt;P&gt;I validate with:  &lt;CODE&gt;|inputlookup assets&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If I look at the CSV file at command line, it has All the columns (required plus additional).&lt;/P&gt;

&lt;P&gt;If I look in GUI under lookup definitions, it only shows the required fields listed.&lt;/P&gt;

&lt;P&gt;How can I get Splunk to acknowledge my additional columns?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Darla&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 17:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208983#M61031</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2016-02-19T17:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my additional columns in my asset lookup not showing in Splunk Web?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208984#M61032</link>
      <description>&lt;P&gt;How were the new columns added, directly updating the lookup table file? Can you verify if the same copy of lookup was updated (check the full path of lookup in Settings-&amp;gt;Lookups-&amp;gt;Lookup table files)?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 17:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208984#M61032</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-02-19T17:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my additional columns in my asset lookup not showing in Splunk Web?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208985#M61033</link>
      <description>&lt;P&gt;If you are referring to the Assets in ES, you can't add additional fields for use in ES :&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields"&gt;http://docs.splunk.com/Documentation/ES/4.0.1/User/AssetandIdentityCorrelation#Asset_lookup_fields&lt;/A&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;The fields allowed in an asset list are set by Enterprise Security and cannot be changed. Unsupported and nonstandard fields will be discarded. The first line of any asset file is a column header, and must list all of the asset fields.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 19 Feb 2016 17:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208985#M61033</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2016-02-19T17:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why are my additional columns in my asset lookup not showing in Splunk Web?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208986#M61034</link>
      <description>&lt;P&gt;I have resolved my own issue.  These additional columns came after I initially implemented the asset lookup table.  I needed to reload apps from my deployment server to the search heads to get the latest data.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 18:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-my-additional-columns-in-my-asset-lookup-not-showing-in/m-p/208986#M61034</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2016-02-19T18:01:16Z</dc:date>
    </item>
  </channel>
</rss>

