Knowledge Management

How is the outputlookup command is configured?

splunkettes
Path Finder

Does anyone know how the outputlookup command is configured? commands.conf does not reference a python script for it. I want to change how new files are created so that they are private and assigned to an owner. 

Labels (1)
Tags (2)
0 Karma
1 Solution

splunkettes
Path Finder

Decided to resolve the issue by creating a custom command to reassign lookup files from nobody to their proper owner based on results of splunk search. 

View solution in original post

splunkettes
Path Finder

Decided to resolve the issue by creating a custom command to reassign lookup files from nobody to their proper owner based on results of splunk search. 

richgalloway
SplunkTrust
SplunkTrust
Outputlookup is a built-in command without an external Python script.
---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkettes
Path Finder

Thanks @richgalloway for your response. I was wondering if there is a way to modify Splunk's built in commands or at least override them with my own process. I have  a custom command that I have created that does what I want the outputlookup command to do but it would require all users to use the new command. Ideally, I would allow users to continue with the outputlookup command but change how it functions so that new files are stored in the etc/<user>/<app>/lookups directory instead of the etc/<app>/lookups directory. 

0 Karma

aayushisplunk1
Path Finder

Hi @splunkettes 

Please guide how you created the custom search command similar to outputlookup command. 

 

0 Karma

sftr
Observer

 

For your use case, this configuration appears to be available from within the limits.conf file:

https://docs.splunk.com/Documentation/Splunk/latest/Admin/limitsconf#.5Boutputlookup.5D

 

[outputlookup]
create_context = user

 

per the documentation:

[outputlookup]
create_context = [app|[user|system] * Specifies the context where the lookup file will be created for the first time. If there is a current application context and the following options, file will be created under: * app  : etc/apps/<app>/lookups * user  : etc/users/<user>/<app>/lookups Otherwise, file will be created under: * system : etc/system/local/lookups * Default: app

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There's no way to override a built-in command.  Your users will have to learn to use myoutputlookup just as they once learned to use outputlookup.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...