Getting Data In

Steps to use included Lookup tables that come with Splunk enterprise & ES

SamHTexas
Builder

Steps to use included Lookup tables that come with Splunk enterprise & ES. I have over 100 Lookup tables that I have in Splunk Enterprise & about 100 Lookup tables with ES. How ready are they to be used. What else do I have to do in order to put them to a good use?

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

I'd start to check which ones are automatically updated by scripts or scheduled searches: these lookups don't need maintenance and it's better not touching them.

Then you should understand which of the remaining ones are still in use or not , which ones are in apps that you don't use and, more important thing, which ones you have to manually maintain.

When you'll have a compete situation, you'll be able to manage your lookups, eventually using the Lookup Editor App, but the first thing is a complete situation.

Ciao.

Giuseppe

SamHTexas
Builder

The information about which is supported via a script or automatically found in the properties of each look up right? Or found by trying to edit one? I am checking them. Grazie.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi, @SamHTexas ,

no they aren't in the properties, you have to search in the scheduled searches.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

One more question please. So where are the KVstore based & scripted based located? 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

all the lookups (file, kv-store, script, etc...) are located on the Search Heads.

Ciao and happy splunking.

Giuseppe

P.S.: if the answer solves your need, please accept it for the other people of Community and Karma Points are appreciated 😉

See next time!

0 Karma

SamHTexas
Builder

In the Splunk environment I inherited. They are  on SHs & many on the ES server. Would the scripted & KV store be list under the Lookup Definitions? Grazie mille.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

yes, you can find them in the Lookup Definitions.

If you have a Search Head Cluster, you have to search Lookups definitions in only one of them because they are replicated on the other SHs

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...