Getting Data In

Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups

mcm10285
Communicator

Does splunk read $SPLUNKHOME/etc/apps/search/lookups in a special manner? I placed a csv file in that directory of a search head to be monitored and it seems like it is not being indexed, or at least it's not searchable. Using it as an inputlookup works though. I want to monitor that file and use it in a form search, an inventory search.

Checked /var/log/splunk/splunkd.log, below is the only log found on the directory/path where the file is:

INFO TailingProcessor - Parsing configuration stanza: monitor:///splunksearches/SH/etc/apps/search/lookups/filename.csv

INFO TailingProcessor - Adding watch on path:///splunksearches/SH/etc/apps/search/lookups/filename.csv

Tags (2)
0 Karma

mcm10285
Communicator

somewhow this just worked..might have been a delayed indexing...

0 Karma

lukejadamec
Super Champion

Using tail for a one time file index routine is not the best way to go about it.
Try it from the commandline - see this post
splunk-base.splunk.com/answers/6922/how-to-ask-splunk-to-index-a-file-using-the-cli

0 Karma

mcm10285
Communicator

tried the CLI and returned the message below

In handler 'monitor': Cannot create another input with the name "/splunksearches/SH/etc/apps/search/lookups/IP_Blocklist.csv", one already exists.

However, when I checked, the data is already indexed. Wonder how long it took.

Thanks for the suggestions anyway.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Start your search with inputlookup, that'll give you the file in Splunk to continue your search:

| inputlookup file_name | search something or other

mcm10285
Communicator

I don't. I just placed a file in the lookups folder and I want to index that.

Input lookup needs a search against it. I need to search on the file itself.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Why would you index a lookup? If you want to start searches with that data, just use inputlookup.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...