<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I upload &amp; Replace lookup files on a weekly basis? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40589#M9353</link>
    <description>&lt;P&gt;Thanks I'll try these steps and report back.  I assumed that if the file was locked then I wouldn't be able to rename either.  It's a Windows server.&lt;/P&gt;

&lt;P&gt;I was fairly certain credentials were in place but I'll investigate that again first if you feel Splunk shouldn't be locking the file.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2011 07:14:16 GMT</pubDate>
    <dc:creator>srw46</dc:creator>
    <dc:date>2011-07-12T07:14:16Z</dc:date>
    <item>
      <title>How can I upload &amp; Replace lookup files on a weekly basis?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40587#M9351</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;I'm using a lookup table that is subject to the occasionally change.  I've been trying to setup a weekly job to replace the existing file with a newer version but the batch job fails on 'access denied' because the file is apparently in use (by Splunk).&lt;/P&gt;

&lt;P&gt;I'm trying to drop the csv file right on top of the other one and overwrite in &lt;CODE&gt;\etc\apps\search\lookups&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there anyway I can get around this or another angle I should take?  Many thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2011 11:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40587#M9351</guid>
      <dc:creator>srw46</dc:creator>
      <dc:date>2011-07-11T11:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload &amp; Replace lookup files on a weekly basis?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40588#M9352</link>
      <description>&lt;P&gt;I've not known Splunk to lock lookup files, even while in use during a search.  Is this on a Unix or a Windows indexer?  &lt;/P&gt;

&lt;P&gt;Best practice in this situation would probably be a multiple-setup process&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Upload new lookup under a temporary name&lt;/LI&gt;
&lt;LI&gt;Rename existing lookup to a different name&lt;/LI&gt;
&lt;LI&gt;Rename new lookup to the "correct" name&lt;/LI&gt;
&lt;LI&gt;Delete the old lookup&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;These steps make your change more likely to be atomic and less likely to impact searches that are running during your update or that start while your update is happening.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2011 14:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40588#M9352</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-07-11T14:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can I upload &amp; Replace lookup files on a weekly basis?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40589#M9353</link>
      <description>&lt;P&gt;Thanks I'll try these steps and report back.  I assumed that if the file was locked then I wouldn't be able to rename either.  It's a Windows server.&lt;/P&gt;

&lt;P&gt;I was fairly certain credentials were in place but I'll investigate that again first if you feel Splunk shouldn't be locking the file.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2011 07:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-upload-Replace-lookup-files-on-a-weekly-basis/m-p/40589#M9353</guid>
      <dc:creator>srw46</dc:creator>
      <dc:date>2011-07-12T07:14:16Z</dc:date>
    </item>
  </channel>
</rss>

