All Apps and Add-ons

Will changing a lookup file persist on app update?

aelliott
Motivator

We have a need to change an out of the box lookup file within Splunk_TA_Windows, this lookup file (windows_signatures.csv) has a column called "action" that is only filled out on Windows 2003 events. Actions such as created, modified, deleted, etc.

These actions are needed to be set in order to show up within the Network Changes dashboard in Splunk Enterprise Security.

If we were to ever update this app in the future to a later version, will it overwrite our lookup file changes?

1 Solution

strive
Influencer

Yes, upgrading app overrides the changes.

I did a quick test. Downloaded and installed version 4.6.6. Made some changes to the CSV file that you mentioned. Downloaded the version 4.6.7 and upgraded the app. The changes made by me were overwritten.

View solution in original post

strive
Influencer

Yes, upgrading app overrides the changes.

I did a quick test. Downloaded and installed version 4.6.6. Made some changes to the CSV file that you mentioned. Downloaded the version 4.6.7 and upgraded the app. The changes made by me were overwritten.

strive
Influencer

I suppose this will be the case with all the app upgrades.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...