Splunk Search

Can we update a lookup CSV file through a URL in splunk

skhan28
Explorer

I have CSV inventory  file which is dynamic and same needs to updated in splunk manually, Is there a way  to integrate the URL  with splunk  to update lookup file 

Labels (1)
Tags (1)
0 Karma
1 Solution

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 .. i assume that the inventory file is dynamic and you are manually loading this file to splunk and using it as a lookup file.

to avoid the manual file uploading, you can create the file directly at the lookup files location(thru some script or the application which creates the file can save/send to this path )

$SPLUNK_HOME\etc\apps\<yourApp>\lookups\lookup-name.csv

once its done, you can use the "lookup" or "inputlookup" commands

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 As per my understanding, Splunk Cloud is managed by Splunk Guys and we can not get access to those systems. 

but, you can work with Splunk Support and send the csv files to the correct location(thru some scripting or thru some methods which Splunk Support suggests).

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

skhan28
Explorer

Sure @inventsekar ,  Thanks for the solution, I'll check with splunk support for access 

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...