<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Edit an Automatic Lookup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42684#M9989</link>
    <description>&lt;P&gt;Wow, thanks for this tip. That sure sounds like a bug, but this answer is 2 years old and this behavior is still present in 5.0.2. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 May 2013 15:21:30 GMT</pubDate>
    <dc:creator>twinspop</dc:creator>
    <dc:date>2013-05-24T15:21:30Z</dc:date>
    <item>
      <title>Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42672#M9977</link>
      <description>&lt;P&gt;I have an automatic lookup in which i need to rename one of the lookup fields. &lt;/P&gt;

&lt;P&gt;Right now whenever a search runs that has source="wsus" the automatic lookup correlates the hostname from the event with the hostname in the lookup file and adds both a business and sub_business field to the event. I need to rename the business field to "newbusiness", however in doing so, it seems as if the old automatic lookup field names are actually part of the event.&lt;/P&gt;

&lt;P&gt;I was under the assumption that automatic lookups run at search time. Am I mistaken? Even after completely deleting the automatic lookup both the business, and sub_business fieldS still appear in the events, and if I try to rename the business field to newbusiness in the automatic lookup , when I run a search for source="wsus" it still returns only business and sub_business.&lt;/P&gt;

&lt;P&gt;Any suggestions? Am I overlooking something? Your help is much appreciated.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2011 05:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42672#M9977</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-11T05:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42673#M9978</link>
      <description>&lt;P&gt;Lookups only run at search time, so if the fields are getting looked up and added to the event, it seems like there's some configuration problem, perhaps in a different app or a private user context.&lt;/P&gt;

&lt;P&gt;Note that a lookup can be configured to output the field names differently from what's in the file, e.g.:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LOOKUP-1 = mylookup infield1 OUTPUT filefieldname AS displayfieldname file2 AS displayfield2
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 11 Feb 2011 05:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42673#M9978</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-11T05:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42674#M9979</link>
      <description>&lt;P&gt;Thanks for your quick response. Do have any suggestions where to begin troubleshooting a configuration issue? &lt;BR /&gt;
I understand that I can rename the output field names differently than what is in the file, however this doesnt really seem to be the issue. Regardless of what I put only the original field names appear.&lt;/P&gt;

&lt;P&gt;I should also note that this is source="wsus" is in a summary index, but I figured that shouldn't make a difference.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2011 05:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42674#M9979</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-11T05:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42675#M9980</link>
      <description>&lt;P&gt;When troubleshooting configuration changes that don't seem to apply, I'm a big fan of frequent restarts and (on linux) "cd /opt/splunk/etc &amp;amp;&amp;amp; grep -R sub_business" or (on windows) "cd c:\Program Files\Splunk\etc &amp;amp;&amp;amp;  findstr /snip sub_business &lt;EM&gt;.&lt;/EM&gt;"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42675#M9980</guid>
      <dc:creator>David</dc:creator>
      <dc:date>2020-09-28T09:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42676#M9981</link>
      <description>&lt;P&gt;Oh yeah, have you restarted? Also, do you happen to have a distributed environment, or just a single server?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2011 08:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42676#M9981</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-11T08:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42677#M9982</link>
      <description>&lt;P&gt;Thanks. I've restarted a few times but nothing seem to took. Gkanapathy - to answer your question, yes this is running in a distributed environment.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2011 21:31:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42677#M9982</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-11T21:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42678#M9983</link>
      <description>&lt;P&gt;A few more findings. After doing some investigating I've realized i'm actually running the automatic lookup on sourcetype (not source), which means it's running the lookup on the scheduled searches prior to inserting them into the summary index. That explains the stored fields. &lt;/P&gt;

&lt;P&gt;However my question remains, Can you run an automatic lookup on a summary index? I've created a new automatic lookup with source=wsus but when i run it on the summary index, no fields are added to the events.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2011 22:03:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42678#M9983</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-11T22:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42679#M9984</link>
      <description>&lt;P&gt;I guess you could run a lookup on a summary index, but the "source" is the name of the job that inserted the data, and that's probably what you need to base it on.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2011 02:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42679#M9984</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-12T02:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42680#M9985</link>
      <description>&lt;P&gt;I'll continue to poke around and see if I find anything. Just to confirm the job name is indeed WSUS and it's displaying as source=wsus (and returning) events in the summary index&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2011 04:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42680#M9985</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-12T04:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42681#M9986</link>
      <description>&lt;P&gt;Uh, and are you generating the summary using stats or sistats (or another si command)?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2011 04:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42681#M9986</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-02-12T04:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42682#M9987</link>
      <description>&lt;P&gt;We're actually just using the | table field1, field2, field3, field4 to dump those records into the summary&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2011 04:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42682#M9987</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-12T04:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42683#M9988</link>
      <description>&lt;P&gt;I figured out the solution to this problem.&lt;/P&gt;

&lt;P&gt;When defining a source in an automatic lookup they are case sensitive. WSUS != wsus. I defined my automatic lookup to look for source=wsus when all my events were tagged with source=WSUS . &lt;/P&gt;

&lt;P&gt;Somewhat of a minor annoyance and was a litle more of a headache to figure out than I would have liked.&lt;/P&gt;

&lt;P&gt;I wish there was a little more consistency in the way that Splunk handles case sensitivity and this is a perfect example. &lt;/P&gt;

&lt;P&gt;If from a splunk search I can search for sourec=wsus and it'll return something that is defined as source=WSUS, shouldn't the same logic apply to an automatic lookup?&lt;/P&gt;

&lt;P&gt;Again, minor annoyance but hopefully this saves someone some time if you run into the same problem.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2011 04:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42683#M9988</guid>
      <dc:creator>zschmid</dc:creator>
      <dc:date>2011-02-16T04:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Edit an Automatic Lookup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42684#M9989</link>
      <description>&lt;P&gt;Wow, thanks for this tip. That sure sounds like a bug, but this answer is 2 years old and this behavior is still present in 5.0.2. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 15:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Edit-an-Automatic-Lookup/m-p/42684#M9989</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2013-05-24T15:21:30Z</dc:date>
    </item>
  </channel>
</rss>

