Getting Data In

Where to keep the lookup file in a clustered environment

surekhasplunk
Communicator

Hello,

We are moving from single deployment to clustered environment. 

Current scenario: for one of my dashboards i was getting the lookup file created by running a python script. using a cronjob. Since i dont want it to be indexed, i was just creating the file and placing it in the lookups folder of one of the apps where the dashboard is there. 

Now when i move to clustered environment how and where do i place the script to generate the lookup 

and where can i save the lookup file to automatically get shared in all the searh heads. 

thanks

 

Labels (2)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @surekhasplunk,

Since Splunk Search Head Cluster will not detect changes you make without Web UI or REST, you have two options;

1- You can create a custom search command runs your python script and than pipe to outputlookup. With this way the cluster will replicate lookup across members.  

2- Running python script on every search head with cronjob.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

surekhasplunk
Communicator

Hello @scelikok 

Thank you so much for your reply. 

for 1st point, if you could you please give an example snippet, that would be great

Thanks 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...