Splunk Search

Can a lookup be recreated and use the existing lookup definition?

leftinnerouter
Explorer

The scenario is, 

A lookup csv has become unreadable. A lookup definition exists for it.

The lookup was deleted and recreated. The existing definition was not changed.

 

My question is: Can a lookup be recreated and use the existing lookup definition?

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

I lookup definition just points to a CSV on the file system. If that CSV is broken in some way and 'replaced' on the file system, then the new one will be used. It may required the Splunk environment to be refreshed, there may be a caching issue there, but if you are unable to refresh the environment easily, then simply upload the new CSV and change the associated filename in the lookup definition to use the new CSV. In a clustered environment the lookup will need to be propagated between the search heads during replication.

 

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

I lookup definition just points to a CSV on the file system. If that CSV is broken in some way and 'replaced' on the file system, then the new one will be used. It may required the Splunk environment to be refreshed, there may be a caching issue there, but if you are unable to refresh the environment easily, then simply upload the new CSV and change the associated filename in the lookup definition to use the new CSV. In a clustered environment the lookup will need to be propagated between the search heads during replication.

 

 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...