Security

how do I check if a lookup table get updated with any output lookup command

karu0711
Communicator

I have lookup table in splunk.
I want check if ever been update in Splunk using output lookup command

Labels (1)
0 Karma

_JP
Contributor

This solved question seems to be what you're looking for:

 

Solved: How to get the Audit for Lookup files modification... - Splunk Community

If you don't want any changes at all, and you're on a *nix system, can you deploy your lookup with read-only permissions on the file within the app?

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...