Getting Data In

Lookup file updates not working

jiaqya
Builder

I have a lookup created from a CSV file.

i put in entries
1
2
3
4
5

When i do a search, i can find these values.

now ,next day i add a new entry 6 and save the csv file.

i dont see the search showing 6, it only shows 1-5

can you help me fix this, it seems the lookup file updates are not being honored...

Tags (1)
0 Karma

splunker12er
Motivator

you can place your lookup file in the below directory and can access from search query

location:

D:\Program Files\Splunk\etc\apps\search\lookups\example.csv

search query :

|inputlookup example.csv
0 Karma

jiaqya
Builder

Yes, this is exactly how i have done it.
now when i do changes to this file, i dont see the changes.

|inputlookup file.csv

0 Karma

jiaqya
Builder

Found the answer.

i had the same lookup name file from 2 different locations . i was updating one of the file and so that was considered by splunk as not primary , so it was not showing.

i delete the duplicate entry and now i can see the new entry...

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...