Splunk Search

Can we update a lookup CSV file through a URL in splunk

skhan28
Explorer

I have CSV inventory  file which is dynamic and same needs to updated in splunk manually, Is there a way  to integrate the URL  with splunk  to update lookup file 

Labels (1)
Tags (1)
0 Karma
1 Solution

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 .. i assume that the inventory file is dynamic and you are manually loading this file to splunk and using it as a lookup file.

to avoid the manual file uploading, you can create the file directly at the lookup files location(thru some script or the application which creates the file can save/send to this path )

$SPLUNK_HOME\etc\apps\<yourApp>\lookups\lookup-name.csv

once its done, you can use the "lookup" or "inputlookup" commands

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

skhan28
Explorer

Thanks @inventsekar for the solution, but we are using splunk cloud which is managed by Splunk so  will they  allow us to perform these steps in splunk server, Will they grant us access for splunk cloud 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @skhan28 As per my understanding, Splunk Cloud is managed by Splunk Guys and we can not get access to those systems. 

but, you can work with Splunk Support and send the csv files to the correct location(thru some scripting or thru some methods which Splunk Support suggests).

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

skhan28
Explorer

Sure @inventsekar ,  Thanks for the solution, I'll check with splunk support for access 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...