Getting Data In

How to add a CSV lookup table - Splunk Light Free eval

L479
Engager

How can a CSV based lookup table be added to Splunk Light Free; and are lookup tables supported in Splunk Light Free?

We've 30+ ones to add and would like a faster way such as the web interface instead of configuration file editing.

0 Karma

jphohloch
Engager
0 Karma

inventsekar
SplunkTrust
SplunkTrust

http://docs.splunk.com/Documentation/SplunkLight/6.4.2/References/Listofsearchcommands
there is no lookup command on the list of available commands on Splunk Light.

0 Karma

waechtler
Path Finder

Maybe, but it works

0 Karma

inventsekar
SplunkTrust
SplunkTrust

oh ok.. thanks.

0 Karma

waechtler
Path Finder

splunk light does support lookups, you just have to configure them manually:

in ~etc/apps/search/lookups add your .csv file:
mylookup.csv

in ~etc/apps/search/local/transforms.conf:

[mylookup]
filename = mylookup.csv

It will also work if placed in app specific directories

0 Karma

sophy
Splunk Employee
Splunk Employee

The current version of Splunk Light does not support lookup tables.

yschiff
New Member

Does Splunk Light still not support lookup tables? I'm looking to use an external source to correlate the IP addresses from my firewall logs to the DNS names of the matching computers. Is there another way to do this in Light?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...