Splunk Enterprise

Splunk Look up Definitions

keerthana_Reddy
New Member

Hello,

I have created a splunk look up table file( file is in csv format )and now Iam trying to create a look up definition. 

But i couldn't create lookup definition because when i tried searching for the look up file , i couldn't get that file in my drop down menu to select.

what could be the reason. can anyone help with this 

 

Thanks in advance

0 Karma

bowesmana
SplunkTrust
SplunkTrust

How did you create the lookup

  • by uploading a CSV
  • using  the lookup editor
  • using outputlookup

which app did you create the lookup in and what app are you in when trying to make the lookup definition.

If yo go to the list of lookup files (Lookups->Lookup table files) can you see the lookup there and what are its permissions - make sure you look for all lookups visible in all apps - and check what app your lookup file is in

 

0 Karma

keerthana_Reddy
New Member

Hii Bowesmana, Thanks for your reply

I created the look up table file by uploading the csv file. 

and iam looking in the same app as the one that i created the look up table.

I am actually supposed to get the data from production splunk. so i have very limited access.

The look up table file i created has private access which is visible only to me . would that be an issue ?

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

A private lookup created in App A can ONLY be seen in app A, so if you try to create the lookup definition in app B, then it will not show the CSV in the dropdown 

bowesmana_0-1714951553275.png

If your lookup is listed like the above, your  username (red) and app (blue), then I believe it should be possible to create a definition in the same app for a private lookup - so if you cannot see your lookup in the dropdown, it may be a result of permissions - I am not sure, but if you can change your lookup permissions to app, you could see if that changes it.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...