Splunk Answers-a-thon!

How to create and manage lookup tables?

yeasuh
Splunk Employee
Splunk Employee

How to create and manage lookup tables?

Labels (2)
Tags (1)
0 Karma

Brett
SplunkTrust
SplunkTrust
0 Karma

RobertMarks
Observer

You can manage a lookup table in the settings tab. You can update or write to a lookup either by uploading them or using the "| outputlookup" command. You can also do this on the backend under the directory $SPLUNK_HOME/etc/system/lookups/ , or in $SPLUNK_HOME/etc/<app_name>/lookups/ if the lookup belongs to a specific app. You can also list lookups using the REST api

You can access your lookup table at the search bar using "| lookup" or "| inputlookup"
Additionally you can set automatic lookups under the fields options. These will apply to a sourcetype kind at search time like how a calculated field or field extraction would work. 

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques

Hello! We are excited to kick off a new series of blogs from SplunkTrust member ITWhisperer, who demonstrates ...

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...