Alerting

updating a lookup table by external means

aniketb
Path Finder

Hi,

I have a lookup table of trusted hosts. This is being used in an alert to match for entries. Since this is a learning phase, I have to keep updating my lookup table of trusted hosts.

If I just delete the .csv file and add a new updated .csv file with same name, will the alert stay unaffected? Or I have to reconfigure the alert after every update to the lookup file? Does any other way exist for this?

Tags (3)
1 Solution

hexx
Splunk Employee
Splunk Employee

Updating a lookup table file by external means should be no problem as long as the name of the file remains the same. Splunk will re-read the file every time it needs to be used if it's very small, or reload it from disk when a change is detected if it's large.

View solution in original post

bhupalbobbadi
Path Finder

I have a simple 2 field csv file and is configured with lookup table, when I add new line to the csv file it is not reflecting in search. Do I need to do anything manually here?

0 Karma

hexx
Splunk Employee
Splunk Employee

Updating a lookup table file by external means should be no problem as long as the name of the file remains the same. Splunk will re-read the file every time it needs to be used if it's very small, or reload it from disk when a change is detected if it's large.

aniketb
Path Finder

Thanks! I just deleted and replaced the file and still everything runs smoothly!

0 Karma

bhupalbobbadi
Path Finder

I have a simple 2 field csv file and is configured with lookup table, when I add new line to the csv file it is not reflecting in search. Do I need to do anything manually here?

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...