<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lookup: CSV file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248431#M74145</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Mar 2016 14:28:35 GMT</pubDate>
    <dc:creator>htkwan</dc:creator>
    <dc:date>2016-03-15T14:28:35Z</dc:date>
    <item>
      <title>Lookup: CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248428#M74142</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I've configured lookup, using a csv file. I've loaded the csv file, configure the lookup definition &amp;amp; automatic lookup. It works okay. When there are changes in th csv file (i.e. add in new rows), how can i do a reload? Thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2016 13:34:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248428#M74142</guid>
      <dc:creator>htkwan</dc:creator>
      <dc:date>2016-03-15T13:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup: CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248429#M74143</link>
      <description>&lt;P&gt;You can either restart your Splunk server, or use the debug/refresh URL ...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &lt;A href="http://splunkweb-url:8000/en-US/debug/refresh" target="test_blank"&gt;http://splunkweb-url:8000/en-US/debug/refresh&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This command will reload many static entities, such as lookups, transforms, ....&lt;BR /&gt;
You can as well trigger the lookup entity directl., which can be done by one of the following commands (I'm not sure if the first one is sufficient, hence both - but you could try with the first one only)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &lt;A href="http://localhost:8000/en-US/debug/refresh?entity=admin/lookup-table-files" target="test_blank"&gt;http://localhost:8000/en-US/debug/refresh?entity=admin/lookup-table-files&lt;/A&gt;
 &lt;A href="http://localhost:8000/en-US/debug/refresh?entity=admin/transforms-lookup" target="test_blank"&gt;http://localhost:8000/en-US/debug/refresh?entity=admin/transforms-lookup&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 15 Mar 2016 14:05:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248429#M74143</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2016-03-15T14:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup: CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248430#M74144</link>
      <description>&lt;P&gt;If you've access to file system on your Splunk servers, you can update the lookup csv file directly from path $SPLUNK_HOME/etc/apps/YourAppName/lookups folder, no reload required.&lt;/P&gt;

&lt;P&gt;If you don't, then you can use lookup editor apps such as "&lt;A href="https://splunkbase.splunk.com/app/1724/"&gt;Lookup File Editor App&lt;/A&gt;" OR Lookup Updater dashboard of Sideview Utils.&lt;/P&gt;

&lt;P&gt;Last option would be to delete the lookup table file and re upload with same name with updated content.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2016 14:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248430#M74144</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-03-15T14:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Lookup: CSV file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248431#M74145</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2016 14:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Lookup-CSV-file/m-p/248431#M74145</guid>
      <dc:creator>htkwan</dc:creator>
      <dc:date>2016-03-15T14:28:35Z</dc:date>
    </item>
  </channel>
</rss>

