Getting Data In

Lookup file updates not working

jiaqya
Builder

I have a lookup created from a CSV file.

i put in entries
1
2
3
4
5

When i do a search, i can find these values.

now ,next day i add a new entry 6 and save the csv file.

i dont see the search showing 6, it only shows 1-5

can you help me fix this, it seems the lookup file updates are not being honored...

Tags (1)
0 Karma

splunker12er
Motivator

you can place your lookup file in the below directory and can access from search query

location:

D:\Program Files\Splunk\etc\apps\search\lookups\example.csv

search query :

|inputlookup example.csv
0 Karma

jiaqya
Builder

Yes, this is exactly how i have done it.
now when i do changes to this file, i dont see the changes.

|inputlookup file.csv

0 Karma

jiaqya
Builder

Found the answer.

i had the same lookup name file from 2 different locations . i was updating one of the file and so that was considered by splunk as not primary , so it was not showing.

i delete the duplicate entry and now i can see the new entry...

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...