Splunk Enterprise

Upload/update lookup file using rest API

jpillai
Path Finder

What is the recommended way to upload / update an existing lookup file through rest api.

I tried using lookup endpoints but it doesnt seem to be working. 

https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/9.2/knowledge-end...

In short, I have a lookup file, abc.csv in search application under my ownership. I now need to overwrite with an updated file. How can we do this using rest api?

Labels (2)
Tags (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... this is tricky because the endpoints for lookup table files require you to first upload the file to the server using another channel. Then with API you point Splunk to such file and it copies the file into its own directory.

You can't directly upload a lookup file into Splunk.

If I  remember correctly, the lookup editor app had API which allowed for overwriting lookups directly but they might not be documented.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...