Getting Data In

Lookup file updates not working

jiaqya
Builder

I have a lookup created from a CSV file.

i put in entries
1
2
3
4
5

When i do a search, i can find these values.

now ,next day i add a new entry 6 and save the csv file.

i dont see the search showing 6, it only shows 1-5

can you help me fix this, it seems the lookup file updates are not being honored...

Tags (1)
0 Karma

splunker12er
Motivator

you can place your lookup file in the below directory and can access from search query

location:

D:\Program Files\Splunk\etc\apps\search\lookups\example.csv

search query :

|inputlookup example.csv
0 Karma

jiaqya
Builder

Yes, this is exactly how i have done it.
now when i do changes to this file, i dont see the changes.

|inputlookup file.csv

0 Karma

jiaqya
Builder

Found the answer.

i had the same lookup name file from 2 different locations . i was updating one of the file and so that was considered by splunk as not primary , so it was not showing.

i delete the duplicate entry and now i can see the new entry...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...