Splunk Enterprise Security

Unable to export manged lookup csv in Splunk Enterprise Security

nabeel652
Builder

I have a custom lookup on my ES search-head. I have added it to manged lookups and it shows up fine in the Content Management Dashboard. However When I try to export it as an app i. e. I select it and then in "Edit Selection" dropdown at the top I select Export. It exports it the app fine. But when I download the app and open it it has only two folders "default" and "meta" and in default it has transforms.conf as expected. But what I'm missing is the .csv file. The documentation says that when you export a managed lookup the csv file will be exported but it is NOT. (I'm onES 6.0).
The like to docs where it says the csv will be exported with managed lookups:

https://docs.splunk.com/Documentation/ES/6.0.0/Admin/Export
alt text

0 Karma

skalliger
Motivator

Can you show us your permissions of that lookup definition? Is it shared globally and also assigned to the correct app?
Usually, what you want to do (atleast can do), is move all your asset and identity lookups into a single app (identity management).

Skalli

0 Karma

nabeel652
Builder

Hi @skalliger

It's not about any specific managed lookup. You can pick up any lookup from the content management dashboard and try to export it. It will not be exported with the .csv file.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...