Splunk Enterprise Security

Unable to export manged lookup csv in Splunk Enterprise Security

nabeel652
Builder

I have a custom lookup on my ES search-head. I have added it to manged lookups and it shows up fine in the Content Management Dashboard. However When I try to export it as an app i. e. I select it and then in "Edit Selection" dropdown at the top I select Export. It exports it the app fine. But when I download the app and open it it has only two folders "default" and "meta" and in default it has transforms.conf as expected. But what I'm missing is the .csv file. The documentation says that when you export a managed lookup the csv file will be exported but it is NOT. (I'm onES 6.0).
The like to docs where it says the csv will be exported with managed lookups:

https://docs.splunk.com/Documentation/ES/6.0.0/Admin/Export
alt text

0 Karma

skalliger
Motivator

Can you show us your permissions of that lookup definition? Is it shared globally and also assigned to the correct app?
Usually, what you want to do (atleast can do), is move all your asset and identity lookups into a single app (identity management).

Skalli

0 Karma

nabeel652
Builder

Hi @skalliger

It's not about any specific managed lookup. You can pick up any lookup from the content management dashboard and try to export it. It will not be exported with the .csv file.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...