Splunk Enterprise

lookup table file location VS lookup definition location

VijaySrrie
Builder

Hi,

I have created a lookup table file via GUI, in the backend it is saved under /opt/splunk/etc/apps/search/lookups

Then I created a lookup definition for the same lookup (which I used in the lookup table files) now I am unable to find an entry for this lookup definition at the backend.

Can you please let me know in which location I should search for the lookup definition entry?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Lookup definitions are in transforms.conf.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Lookup definitions are in transforms.conf.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...