Splunk Enterprise

Upload/update lookup file using rest API

jpillai
Path Finder

What is the recommended way to upload / update an existing lookup file through rest api.

I tried using lookup endpoints but it doesnt seem to be working. 

https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/9.2/knowledge-end...

In short, I have a lookup file, abc.csv in search application under my ownership. I now need to overwrite with an updated file. How can we do this using rest api?

Labels (2)
Tags (3)
0 Karma

burwell
SplunkTrust
SplunkTrust

Have a look at this solution

https://community.splunk.com/t5/Splunk-Search/Can-you-create-modify-a-lookup-file-via-REST-API/m-p/1...

@mthcht wrote a script that works. I modified it a little for my use but it is basically the same solution and works on a single head or on a SHC. The gist is that it loops through and reads the contents in python and then uploads a big string.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... this is tricky because the endpoints for lookup table files require you to first upload the file to the server using another channel. Then with API you point Splunk to such file and it copies the file into its own directory.

You can't directly upload a lookup file into Splunk.

If I  remember correctly, the lookup editor app had API which allowed for overwriting lookups directly but they might not be documented.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...