Splunk Enterprise

How to get the latest version of a lookup file

yossefn
Path Finder

Hi, 

I have a SQL job that exports a .csv table to our file server with one column of user names in the file. This job is running once a day at the morning and writing a new file every day with the same name. Since Iv'e uploaded the file once, I can't see the changes of the new files in the next days. 

Is there any option for me to monitor this file as a lookup and run a searches against the most recent data?

Thank you, 

Yossi. 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If you can have the SQL job write the CSV file to your app's 'lookup' directory then your queries can reference it using the lookup command.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If you can have the SQL job write the CSV file to your app's 'lookup' directory then your queries can reference it using the lookup command.

---
If this reply helps you, Karma would be appreciated.

yossefn
Path Finder

Looks like the SQL will have a little problem to write to a UNIX path, but we'll solve it with different tool to build a job that will copy the lookup file and write it the the Splunk server. 

Thank you @richgalloway for the idea. 

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...