Getting Data In

Steps to use included Lookup tables that come with Splunk enterprise & ES

SamHTexas
Builder

Steps to use included Lookup tables that come with Splunk enterprise & ES. I have over 100 Lookup tables that I have in Splunk Enterprise & about 100 Lookup tables with ES. How ready are they to be used. What else do I have to do in order to put them to a good use?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

I'd start to check which ones are automatically updated by scripts or scheduled searches: these lookups don't need maintenance and it's better not touching them.

Then you should understand which of the remaining ones are still in use or not , which ones are in apps that you don't use and, more important thing, which ones you have to manually maintain.

When you'll have a compete situation, you'll be able to manage your lookups, eventually using the Lookup Editor App, but the first thing is a complete situation.

Ciao.

Giuseppe

SamHTexas
Builder

The information about which is supported via a script or automatically found in the properties of each look up right? Or found by trying to edit one? I am checking them. Grazie.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi, @SamHTexas ,

no they aren't in the properties, you have to search in the scheduled searches.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

One more question please. So where are the KVstore based & scripted based located? 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

all the lookups (file, kv-store, script, etc...) are located on the Search Heads.

Ciao and happy splunking.

Giuseppe

P.S.: if the answer solves your need, please accept it for the other people of Community and Karma Points are appreciated 😉

See next time!

0 Karma

SamHTexas
Builder

In the Splunk environment I inherited. They are  on SHs & many on the ES server. Would the scripted & KV store be list under the Lookup Definitions? Grazie mille.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

yes, you can find them in the Lookup Definitions.

If you have a Search Head Cluster, you have to search Lookups definitions in only one of them because they are replicated on the other SHs

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...