Splunk Cloud Platform

lookup table

iherb_0718
Path Finder

Hello

Within Enterprise Security I have this as the beginning part of my correlation search:

| from inputlookup:access_tracker

I can't seem to find where the contents of this lookup table is. I've gone into SETTINGS < Lookups < and gone through the "lookup table files" and "Automatic Lookups" but could not find anything for access_tracker.

Ideas?

 

Labels (1)
0 Karma

iherb_0718
Path Finder

General_Talos,

Thank you but I'm not looking to add a new lookup file. I am wanting to find out more details on my existing lookup file. 

0 Karma

iherb_0718
Path Finder

Sceikok this would be a static file that was uploaded?  I'm questioning the value of data I see in a field but was wondering if any of that could be dynamically generated by splunk.

 

0 Karma

General_Talos
Path Finder

Access Tracker is part of "Asset and identity" module for Splunk ES app

to access "inputlookup:access_tracker" you 1st need to add asset data/lookup by using

- From the Splunk menu bar, select Settings > Lookups > Lookup table files.
- Click New.
- Select a Destination App of SA-IdentityManagement.
- Select the lookup file to upload.
- Type the Destination filename that the lookup table file should have on the search head. The name should include the filename extension.
- For example, network_assets_from_CMDB.csv
- Click Save to save the lookup table file and return to the list of lookup table files.

Reference : https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Configurenewassetoridentitylist

For more details on "Asset and Identity" Module follow

https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Addassetandidentitydata

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @iherb_0718,

It should be in SA-AccessProtection app Lookup Definitions;

https://splunk_host:8000/en-US/manager/SA-AccessProtection/data/transforms/lookups?ns=SA-AccessProtection&pwnr=-&search=access_tracker

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...