Getting Data In

How to add a CSV lookup table - Splunk Light Free eval

L479
Engager

How can a CSV based lookup table be added to Splunk Light Free; and are lookup tables supported in Splunk Light Free?

We've 30+ ones to add and would like a faster way such as the web interface instead of configuration file editing.

0 Karma

jphohloch
Engager
0 Karma

inventsekar
Super Champion

http://docs.splunk.com/Documentation/SplunkLight/6.4.2/References/Listofsearchcommands
there is no lookup command on the list of available commands on Splunk Light.

0 Karma

waechtler
Path Finder

Maybe, but it works

0 Karma

inventsekar
Super Champion

oh ok.. thanks.

0 Karma

waechtler
Path Finder

splunk light does support lookups, you just have to configure them manually:

in ~etc/apps/search/lookups add your .csv file:
mylookup.csv

in ~etc/apps/search/local/transforms.conf:

[mylookup]
filename = mylookup.csv

It will also work if placed in app specific directories

0 Karma

sophy
Splunk Employee
Splunk Employee

The current version of Splunk Light does not support lookup tables.

yschiff
New Member

Does Splunk Light still not support lookup tables? I'm looking to use an external source to correlate the IP addresses from my firewall logs to the DNS names of the matching computers. Is there another way to do this in Light?

0 Karma
Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...