Hi
I am having a really hard time in understanding the Splunk lookups process from your splunk documentation. I have configured the splunk lookups from an example csv file as per the steps given in the documentation. But not able to search or understand some aspects of it.
I would really appreciate if you could help me in this matter and get these doubts clear so I can be able to search my data from the lookups I have configured,.
Many Thanks!
Hi @ratra_007,
I don't know which documentation you read, anyway here you can find useful documentation at https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Aboutlookupsandfieldactions and see a useful video at https://www.splunk.com/view/SP-CAAAE3F
Antway, in few words:
to enable lookups you have two ways:
then you need to create Lookup Definition [Settings -- Lookups -- Lookup Definitions -- New Lookup Definitions]; remember this otherwise your lookup isn't usable!
At this point you can use lookups in two ways:
in searches using the "| inputlookup" command (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Inputlookup)
or to enrich your search with static data, using the "lookup" command (https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Lookup)
Ciao.
Giuseppe
Could you be more specific, please? What documentation are you following? What exactly is not clear? What is the search you are trying?