- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to create and manage lookup tables?
yeasuh

Splunk Employee
05-30-2023
10:22 AM
How to create and manage lookup tables?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Brett

SplunkTrust
07-19-2023
11:59 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
RobertMarks
Observer
07-19-2023
11:50 AM
You can manage a lookup table in the settings tab. You can update or write to a lookup either by uploading them or using the "| outputlookup" command. You can also do this on the backend under the directory $SPLUNK_HOME/etc/system/lookups/ , or in $SPLUNK_HOME/etc/<app_name>/lookups/ if the lookup belongs to a specific app. You can also list lookups using the REST api
You can access your lookup table at the search bar using "| lookup" or "| inputlookup"
Additionally you can set automatic lookups under the fields options. These will apply to a sourcetype kind at search time like how a calculated field or field extraction would work.
