Getting Data In

Where to keep the lookup file in a clustered environment

surekhasplunk
Communicator

Hello,

We are moving from single deployment to clustered environment. 

Current scenario: for one of my dashboards i was getting the lookup file created by running a python script. using a cronjob. Since i dont want it to be indexed, i was just creating the file and placing it in the lookups folder of one of the apps where the dashboard is there. 

Now when i move to clustered environment how and where do i place the script to generate the lookup 

and where can i save the lookup file to automatically get shared in all the searh heads. 

thanks

 

Labels (2)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @surekhasplunk,

Since Splunk Search Head Cluster will not detect changes you make without Web UI or REST, you have two options;

1- You can create a custom search command runs your python script and than pipe to outputlookup. With this way the cluster will replicate lookup across members.  

2- Running python script on every search head with cronjob.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

surekhasplunk
Communicator

Hello @scelikok 

Thank you so much for your reply. 

for 1st point, if you could you please give an example snippet, that would be great

Thanks 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...