All Apps and Add-ons

How do I refresh a lookup file automatically with Splunk App for Lookup File Editing ?

hinako
Engager

Hi,

I want to refresh a lookup file daily.
How do I do this?

My file type is csv and in a file server.

Thanks,

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hinako,

where does the csv file come from?

if it's in a server or pc folder, you can put it in a folder, read it and override the lookup with a simple scheduled search:

| inputcsv <your_csv_file>
| outputcsv <your-lookup>

eventually adding some check if the csv file is empty or missing.

Ciao.

Giuseppe

hinako
Engager

Hi, @gcusello 

Thank you so much.

My problem has solved.

I appreciate your kindfulness.

 

Thanks,

 

Hinako

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hinako ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...