All Apps and Add-ons

Application Context (ui_displatch_app vs. ui_dispatch_view)

memarshall63
Communicator

Can anyone explain or point to documentation that can explain the ui_displatch_app vs. ui_dispatch_view configuration in savedsearches.conf. I have a search that ultimately results in the line:

| outputlookup creatinapp=true create_empty=false lookup_filename.csv

The saved search is contained in Application_A
The savedsearches.conf also adds the settings:

request.ui_dispatch_app = Application_A
request.ui_dispatch_view = search

I'm not sure why the developer chose 'ui_dispatch_view = search' but the lookup file (lookup_filename.csv) seems to randomly end up in either Application_A/lookups or search/lookups directories. I thought at first that this was the difference between the job being scheduled, and the job being executed by hand. But, maybe that's just a mirage.

The .spec file says this:

request.ui_dispatch_app  = <string>
* Specifies a field used by Splunk UI to denote the app that this search should be dispatched in.
* Default: empty string

request.ui_dispatch_view = <string>
* Specifies a field used by Splunk UI to denote the view this search should be displayed in.
* Default: empty string

I guess I don't understand the difference between an 'app' and a 'view', and neither of those would seem to relate to a outputlookup command.

I'd appreciate the help.

Tags (1)
0 Karma

memarshall63
Communicator

More details:

The key 'requirement' here is to create a lookup file in the same 'app/lookups' directory. I thought that manipulating these values might do that -- but I'm finding that these settings don't seem to have any reliable impact.

At the end of the day -- if you run

|outputlookup lookup_file.csv 

in a search, because the "createinapp' parameter has a default of 'true' -- the outlook file will be created in the lookups folder in the app where the search is running -- NOT in the app where the search is defined.

If you run

|outputlookup createinapp=false lookup_file.csv

in a search, the lookup file will end up in ../system/lookups.

I do not see a way to force a lookup file to end up in a specific applications lookups directory. Anyone have any solutions for that?

0 Karma

memarshall63
Communicator

I'm adding this as a separate question...

0 Karma
Get Updates on the Splunk Community!

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...