Splunk Enterprise

Splunk Look up Definitions

keerthana_Reddy
New Member

Hello,

I have created a splunk look up table file( file is in csv format )and now Iam trying to create a look up definition. 

But i couldn't create lookup definition because when i tried searching for the look up file , i couldn't get that file in my drop down menu to select.

what could be the reason. can anyone help with this 

 

Thanks in advance

0 Karma

bowesmana
SplunkTrust
SplunkTrust

How did you create the lookup

  • by uploading a CSV
  • using  the lookup editor
  • using outputlookup

which app did you create the lookup in and what app are you in when trying to make the lookup definition.

If yo go to the list of lookup files (Lookups->Lookup table files) can you see the lookup there and what are its permissions - make sure you look for all lookups visible in all apps - and check what app your lookup file is in

 

0 Karma

keerthana_Reddy
New Member

Hii Bowesmana, Thanks for your reply

I created the look up table file by uploading the csv file. 

and iam looking in the same app as the one that i created the look up table.

I am actually supposed to get the data from production splunk. so i have very limited access.

The look up table file i created has private access which is visible only to me . would that be an issue ?

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

A private lookup created in App A can ONLY be seen in app A, so if you try to create the lookup definition in app B, then it will not show the CSV in the dropdown 

bowesmana_0-1714951553275.png

If your lookup is listed like the above, your  username (red) and app (blue), then I believe it should be possible to create a definition in the same app for a private lookup - so if you cannot see your lookup in the dropdown, it may be a result of permissions - I am not sure, but if you can change your lookup permissions to app, you could see if that changes it.

Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...