All Apps and Add-ons

Lookup Editor and Alert Manager

logginz85
Explorer

Hi all.

We currently use Alert manager to annotate apps, and for several of them we have a drilldown that inputlookups a lookup table, edits it, then outputlookup it after. This means the team can use drilldowns to verify activity from users or suppress notifications for example.

Due to a small (but inevitable) incident where a lookup table was erased, we are now looking to utilise the Lookup Editor app so as to have some sort of version control.

However looking at it, it seems that version control is only maintained if the table is edited in the Lookup Editor app itself? Does this mean that drilldowns will not cause a backup to be made, and instead we'll have to have a link to this table in the app instead? 

If so thats fine, but can values from an alert be parsed through to edit fields already? Or would any modifications to the tables have to be copy/pasted?

Thanks in advance

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...