Getting Data In

Where to keep the lookup file in a clustered environment

surekhasplunk
Communicator

Hello,

We are moving from single deployment to clustered environment. 

Current scenario: for one of my dashboards i was getting the lookup file created by running a python script. using a cronjob. Since i dont want it to be indexed, i was just creating the file and placing it in the lookups folder of one of the apps where the dashboard is there. 

Now when i move to clustered environment how and where do i place the script to generate the lookup 

and where can i save the lookup file to automatically get shared in all the searh heads. 

thanks

 

Labels (2)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @surekhasplunk,

Since Splunk Search Head Cluster will not detect changes you make without Web UI or REST, you have two options;

1- You can create a custom search command runs your python script and than pipe to outputlookup. With this way the cluster will replicate lookup across members.  

2- Running python script on every search head with cronjob.

 

If this reply helps you an upvote is appreciated.
0 Karma

surekhasplunk
Communicator

Hello @scelikok 

Thank you so much for your reply. 

for 1st point, if you could you please give an example snippet, that would be great

Thanks 

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>