I'm trying to automatize a task that consists in the topics:
-Clean eventdata from Splunk (Done)
-Upload CSV file to replace the data of old version of the file
Is it possible to do the 2nd phase through the command line?
Thanks and regards
csv lookups exists in each of the apps "lookups" directory. This is a dynamic directory and it is just matter of copying to this directory
Depends on the complexity of your Splunk Installation
I use "rsync" in Linux to copy the lookup files, so it updates only when there is a change to file.
The oneshot command may be what you're looking for. Check out http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorfilesanddirectoriesusingtheCLI.