All Apps and Add-ons

"Lookup File Editor" match_type settings

Mockjin
Explorer

Hi,

i am trying the App "Lookup File Editor" and have problems with the match_type settings. Normal lookups can be configured to use match_type=CIDR or something else. I cant find similar settings in the "Lookup File Editor" app from splunkbase. Do i something wrong or is this feature not included?

 

Thanks

 

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

There are no such settings in the Lookup File Editor app.  The app is for modifying a lookup file.  Match_type settings are for lookups, which may or may not correspond to a lookup file.

IOW, lookups are an abstraction, but the Lookup File Editor is for working with a physical data file.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are no such settings in the Lookup File Editor app.  The app is for modifying a lookup file.  Match_type settings are for lookups, which may or may not correspond to a lookup file.

IOW, lookups are an abstraction, but the Lookup File Editor is for working with a physical data file.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Mockjin
Explorer

@richgalloway  thank you for your fast answer 🙂 

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...